{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/feelec-yishu/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:feelec_yishu:feelcrm_os:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-105290"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["feelcrm-os (1.0.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","ssrf"],"_cs_type":"advisory","_cs_vendors":["feelec-yishu"],"content_html":"\u003cp\u003eCVE-2026-105290 identifies a critical server-side request forgery (SSRF) vulnerability within feelcrm-os version 1.0.0. The vulnerability resides in the getCurlData endpoint, specifically within the file App/Feelcrm/Index/Controller/GoogleController.class.php. An attacker can supply a malicious URL through the 'url' argument, which the application then requests on behalf of the server. This allows remote, unauthenticated attackers to interact with internal network resources or external services, potentially leading to unauthorized data exfiltration or access to internal administration interfaces. Public disclosure of the vulnerability has occurred, and as of the publication date, the project maintainers have not released a patch or responded to initial vulnerability reports.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to bypass perimeter security to scan and interact with internal network services that are otherwise inaccessible from the public internet. This can lead to unauthorized access to cloud metadata services, internal API endpoints, or private management interfaces, potentially resulting in complete compromise of the underlying server if secondary vulnerabilities are identified within the internal network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eRestrict outbound network access from the host running feelcrm-os to only essential external services, effectively neutralizing the impact of potential SSRF exploitation.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on the 'url' parameter for the GoogleController endpoint to permit only expected domain patterns.\u003c/li\u003e\n\u003cli\u003eMonitor web access logs for anomalous requests to the '/App/Feelcrm/Index/Controller/GoogleController.class.php' path, particularly those containing suspicious URL parameters or attempts to access internal IP addresses (e.g., 127.0.0.1, 169.254.169.254).\u003c/li\u003e\n\u003cli\u003eMonitor for potential exploitation attempts targeting this specific file until an official vendor patch is released.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-05T11:39:30Z","date_published":"2026-10-05T11:39:30Z","id":"https://feed.craftedsignal.io/briefs/2026-10-feelcrm-ssrf/","summary":"An unauthenticated server-side request forgery (SSRF) vulnerability in feelcrm-os 1.0.0 allows remote attackers to force the server to perform unauthorized HTTP requests by manipulating the url parameter.","title":"SSRF Vulnerability in feelcrm-os via GoogleController","url":"https://feed.craftedsignal.io/briefs/2026-10-feelcrm-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Feelec-Yishu","version":"https://jsonfeed.org/version/1.1"}