CVE-2025-14189

HIGH

Chanjet CRM <20251121 - SQL Injection

Title source: llm
STIX 2.1

Description

A vulnerability was detected in Chanjet CRM up to 20251121. Affected is an unknown function of the file /tools/jxf_dump_table_demo.php. The manipulation of the argument gblOrgID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (5)

Core 5
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.334609
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.334609
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.699133
Issue Tracking issue-tracking
https://github.com/hacker-routing/cve/issues/2

Scores

CVSS v3 7.3
EPSS 0.0026
EPSS Percentile 17.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
Chanjet/CRM 20251121
Published Dec 07, 2025
Tracked Since Feb 18, 2026