CVE-2026-4623 Details
Description
A security vulnerability has been detected in DefaultFuction Jeson-Customer-Relationship-Management-System up to 1b4679c4d06b90d31dd521c2b000bfdec5a36e00. This affects an unknown function of the file /api/System.php of the component API Module. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The identifier of the patch is f76e7123fe093b8675f88ec8f71725b0dd186310/98bd4eb07fa19d4f2c5228de6395580013c97476. It is suggested to install a patch to address this issue.
A server-side request forgery (SSRF) vulnerability exists in DefaultFuction Jeson-Customer-Relationship-Management-System versions prior to 1b4679c4d06b90d31dd521c2b000bfdec5a36e00. The vulnerability is located in the API module, specifically within the '/api/System.php' file. It arises from the application fetching data from remote URLs based on user-supplied parameters, without adequate validation or sanitization. This flaw allows attackers to manipulate the 'url' parameter to direct the server to make requests to unintended destinations, potentially leading to the exposure of sensitive internal data or services.
Users are advised to apply the patch available in the commit 'f76e7123fe093b8675f88ec8f71725b0dd186310' to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 24, 2026CISA-ADP
Assessed Mar 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/DefaultFuction/Jeson-Customer-Relationship-Management-System/ | [email protected] | ProductVendor |
| https://github.com/DefaultFuction/Jeson-Customer-Relationship-Management-System/commit/f76e7123fe093b8675f88ec8f71725b0dd186310 | [email protected] | Source CodeVendor |
| https://github.com/DefaultFuction/Jeson-Customer-Relationship-Management-System/issues/2 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/DefaultFuction/Jeson-Customer-Relationship-Management-System/issues/2#issue-4045330588 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/DefaultFuction/Jeson-Customer-Relationship-Management-System/issues/2#issuecomment-4023480586 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/?ctiid.352482 | [email protected] | Content Wall |
| https://vuldb.com/?id.352482 | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/?submit.775760 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| DefaultFuction Jeson-Customer-Relationship-Management-System | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Mar 24, 2026 | New CVE Received | [email protected] |
Volerion