PT-2025-49402 · Chanjet · Chanjet Crm

Routing_Love

·

Published

2025-12-07

·

Updated

2025-12-11

·

CVE-2025-14189

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Chanjet CRM versions prior to 20251122
Description A SQL injection issue exists in Chanjet CRM. The issue is related to the manipulation of the gblOrgID parameter within the /tools/jxf dump table demo.php file. This manipulation affects an unknown function. The attack can be performed remotely. The exploit is publicly available.
Recommendations Versions prior to 20251122 should be updated. Restrict access to the /tools/jxf dump table demo.php file. Avoid using the gblOrgID parameter until the issue is resolved.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-14189

Affected Products

Chanjet Crm