{"id":"CVE-2021-48008","title":"Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint","summary":"Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint. Attackers can exploit the lack of inp…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-89"],"vendor":"Chanjet Information Technology Co., Ltd.","product":"CRM","affected":["CRM"],"published":"2026-09-18","updated":"2026-09-21","sourceUpdated":"2026-09-21T19:17:01.817","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-48008","references":[{"url":"https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/main/http/vulnerabilities/chanjet-tplus/chanjet-crm-sqli.yaml","label":"disclosure@vulncheck.com"},{"url":"https://www.chanjet.com/","label":"disclosure@vulncheck.com"},{"url":"https://www.cnvd.org.cn/flaw/show/CNVD-2021-12845","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/chanjet-crm-sql-injection-via-get-usedspace-php","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-21T18:27:55.957467Z"},"epss":0.00344,"epssPercentile":0.27909,"ingestedAt":"2026-09-18T19:49:30.580Z","slug":"CVE-2021-48008","body":"## Overview\n\nChanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint. Attackers can exploit the lack of input sanitization or parameterization through UNION-based injection techniques to extract sensitive data from the underlying database. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}