CVE-2026-105389
Received Received - Intake

Unrestricted File Upload in FeelCRM OS

Vulnerability report for CVE-2026-105389, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: VulDB

Description

A security vulnerability has been detected in feelec-yishu feelcrm-os 1.0.0. This issue affects some unknown processing of the file App/Feelcrm/Crm/Controller/UploadController.class.php of the component UploadTicketFile Endpoint. Such manipulation of the argument cmd leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
feelec-yishu feelcrm-os 1.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authenticated unrestricted file upload flaw in feelcrm-os version 1.0.0. It allows attackers with valid credentials to upload malicious files, such as PHP scripts, to a web-accessible directory without proper validation of file extensions or content. The uploaded files can then be executed remotely, leading to potential remote code execution on the server.

Detection Guidance

Check the UploadTicketFile endpoint in feelcrm-os 1.0.0 for unrestricted file uploads. Look for PHP files in the Attachs directory. Verify if filenames are preserved from user input without validation. Inspect the chunked upload endpoint for improper file extension checks.

Impact Analysis

If exploited, this vulnerability could allow attackers to execute arbitrary code on the server with the privileges of the web server process. This may lead to unauthorized access to sensitive data, installation of malware, defacement of the website, or use of the server as a pivot point for further attacks within the network.

Compliance Impact

This vulnerability could lead to data breaches, exposing personal or sensitive information. For GDPR, this may result in unauthorized data processing and potential fines. For HIPAA, it could violate protected health information safeguards, leading to compliance violations and penalties.

Mitigation Strategies

Store user uploads outside the web root. Enforce strict file extension allowlists. Validate file content server-side. Configure the web server to deny script execution in upload directories. Ensure authenticated access is required for uploads.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105389. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart