CVE-2026-86171
Dashboard / Vulnerabilities / CVE-2026-86171
CVE-2026-86171
Summary: DefaultFuction CRM delete.php sql injection
Details: A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86171.json, https://nvd.nist.gov/vuln/detail/CVE-2026-86171, https://vuldb.com/cve/CVE-2026-86171, https://vuldb.com/submit/895743, https://vuldb.com/vuln/399309, https://github.com/DefaultFuction/Customer-Relationship-Management-System/issues/4, https://vuldb.com/vuln/399309/cti
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
