CVE-2026-86170 A weakness has been identified in DefaultFuction CRM… — CVE Notify — TG.ME

🚨 CVE-2026-86170
A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

🎖@cveNotify
GitHub
DefaultFunction Customer Relationship Management System V1.0.0 SQL Injection Vulnerability · Issue #3 · DefaultFuction/Customer…
DefaultFunction Customer Relationship Management System V1.0.0 SQL Injection Vulnerability NAME OF AFFECTED PRODUCT(S) Customer Relationship Management System AFFECTED AND/OR FIXED VERSION(S) V1.0....
September 6, 2026 71