---
id: CVE-2026-105288
title: A vulnerability has been found in feelec-yishu feelcrm-os 1.0.0
summary: >-
  A vulnerability has been found in feelec-yishu feelcrm-os 1.0.0. Affected by
  this vulnerability is the function IndexController::index of the file
  App/ThinkPHP/Common/functions.php of the component Crm Endpoint. Such
  manipulation of the …
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: feelec-yishu
product: feelcrm-os
affected:
  - feelcrm-os 1.0.0
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T10:16:41.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105288'
references:
  - url: 'https://github.com/feelec-yishu/feelcrm-os/'
    label: cna@vuldb.com
  - url: 'https://github.com/feelec-yishu/feelcrm-os/issues/2'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-105288'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/977518'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413469'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413469/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T10:17:16.615Z'
---

## Overview

A vulnerability has been found in feelec-yishu feelcrm-os 1.0.0. Affected by this vulnerability is the function IndexController::index of the file App/ThinkPHP/Common/functions.php of the component Crm Endpoint. Such manipulation of the argument redirect_url leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
