CVE-2026-86172
Dashboard / Vulnerabilities / CVE-2026-86172
CVE-2026-86172
Summary: DefaultFuction CRM delete.php sql injection
Details: A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86172.json, https://nvd.nist.gov/vuln/detail/CVE-2026-86172, https://vuldb.com/cve/CVE-2026-86172, https://vuldb.com/submit/895744, https://vuldb.com/vuln/399310, https://github.com/DefaultFuction/Customer-Relationship-Management-System/issues/5, https://vuldb.com/vuln/399310/cti
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
