CVE-2026-86172 A vulnerability was detected in DefaultFuction CRM… — CVE Notify — TG.ME

🚨 CVE-2026-86172
A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

🎖@cveNotify
GitHub
DefaultFunction Customer Relationship Management System V1.0.0 SQL Injection Vulnerability · Issue #5 · DefaultFuction/Customer…
DefaultFunction Customer Relationship Management System V1.0.0 SQL Injection Vulnerability NAME OF AFFECTED PRODUCT(S) Customer Relationship Management System AFFECTED AND/OR FIXED VERSION(S) V1.0....
September 6, 2026 66