Junglewise Threat Intelligence

CVE-2026-84111: Chanjet CRM SQL injection in jxf_dump_table.php

CVE-2026-84111 · Severity: high · CVSS 7.3 · Published 2026-09-01

Executive brief

Chanjet CRM is a customer relationship management system used by businesses to manage customer interactions and sales data. A critical SQL injection vulnerability in the file jxf_dump_table.php allows remote attackers without authentication to execute arbitrary database commands, potentially exposing all customer data, sales records, and business information stored in the system.

Technical details

The vulnerability is an unauthenticated SQL injection in the gblOrgID parameter of /tools/jxf_dump_table.php. User-supplied input is directly concatenated into SQL queries without proper validation or parameterization. The attack vector is a simple HTTP GET request; no authentication is required and the application explicitly accepts requests with DontCheckLogin=1. An attacker can execute arbitrary SQL commands to read, modify, or delete database records, potentially leading to privilege escalation or remote code execution on the database server. The vendor was contacted early but did not respond, and public exploits are available.

Affected products

  • Chanjet CRM up to 20260707 (including V1.0)

Timeline

  • 2026-07-07: disclosed: Vulnerability report filed by Rain Wu
  • 2026-09-01: advisory: CVE-2026-84111 published

References