CVE-2026-105290
Received Received - Intake

Server-Side Request Forgery in FeelCRM OS

Vulnerability report for CVE-2026-105290, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: VulDB

Description

A vulnerability was determined in feelec-yishu feelcrm-os 1.0.0. This affects an unknown part of the file App/Feelcrm/Index/Controller/GoogleController.class.php of the component getCurlData Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
feelec-yishu feelcrm-os 1.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a blind Server-Side Request Forgery (SSRF) vulnerability in feelcrm-os 1.0.0. It affects the getCurlData endpoint in the GoogleController.class.php file. The vulnerability occurs because the endpoint accepts a user-controlled 'url' parameter and passes it directly to PHP's cURL function without validation. This allows attackers to force the server to make HTTP requests to arbitrary internal or external destinations.

Detection Guidance

To detect this SSRF vulnerability, monitor network traffic for outbound requests originating from the server hosting feelcrm-os 1.0.0, particularly to unusual or internal IP addresses. Check server logs for requests to the /Index/Google/getCurlData endpoint with arbitrary URLs. Use tools like curl to test the endpoint manually: curl -v 'http://<target>/Index/Google/getCurlData?url=http://internal-service' to see if the server attempts to connect to unexpected destinations.

Inspect PHP error logs for cURL-related errors when making requests to the vulnerable endpoint. Network-level detection can involve monitoring egress traffic from the server to identify unauthorized outbound connections.

Impact Analysis

An attacker could exploit this to make the server connect to internal services, potentially discovering internal network structure or triggering actions in other services. While the SSRF is blind (no direct response access), it could enable internal service discovery or state-changing actions if accessible services exist. The impact depends on what internal services the server can access.

Compliance Impact

This SSRF vulnerability could potentially violate compliance with GDPR and HIPAA by enabling unauthorized server-side requests to internal systems. For GDPR, it may lead to unauthorized access to personal data processing systems. For HIPAA, it could allow access to protected health information systems. The lack of input validation and blind SSRF nature makes it harder to detect but still poses risks to data confidentiality and integrity.

Mitigation Strategies

Immediately restrict access to the /Index/Google/getCurlData endpoint by implementing authentication and authorization checks. Update the application to validate and sanitize the 'url' parameter, allowing only specific, trusted domains or IP ranges. Disable cURL functions for user-controlled inputs or implement strict allowlists for URL schemes (e.g., only http/https).

Apply network-level controls to block outbound requests from the server to internal or sensitive IP ranges. Consider upgrading to a patched version if available or applying vendor-supplied fixes. Monitor for unusual network activity as a secondary defense measure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105290. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart