<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Feelec-Yishu - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/feelec-yishu/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 11:39:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/feelec-yishu/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SSRF Vulnerability in feelcrm-os via GoogleController</title><link>https://feed.craftedsignal.io/briefs/2026-10-feelcrm-ssrf/</link><pubDate>Mon, 05 Oct 2026 11:39:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-feelcrm-ssrf/</guid><description>An unauthenticated server-side request forgery (SSRF) vulnerability in feelcrm-os 1.0.0 allows remote attackers to force the server to perform unauthorized HTTP requests by manipulating the url parameter.</description><content:encoded><![CDATA[<p>CVE-2026-105290 identifies a critical server-side request forgery (SSRF) vulnerability within feelcrm-os version 1.0.0. The vulnerability resides in the getCurlData endpoint, specifically within the file App/Feelcrm/Index/Controller/GoogleController.class.php. An attacker can supply a malicious URL through the 'url' argument, which the application then requests on behalf of the server. This allows remote, unauthenticated attackers to interact with internal network resources or external services, potentially leading to unauthorized data exfiltration or access to internal administration interfaces. Public disclosure of the vulnerability has occurred, and as of the publication date, the project maintainers have not released a patch or responded to initial vulnerability reports.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an attacker to bypass perimeter security to scan and interact with internal network services that are otherwise inaccessible from the public internet. This can lead to unauthorized access to cloud metadata services, internal API endpoints, or private management interfaces, potentially resulting in complete compromise of the underlying server if secondary vulnerabilities are identified within the internal network.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Restrict outbound network access from the host running feelcrm-os to only essential external services, effectively neutralizing the impact of potential SSRF exploitation.</li>
<li>Implement strict input validation on the 'url' parameter for the GoogleController endpoint to permit only expected domain patterns.</li>
<li>Monitor web access logs for anomalous requests to the '/App/Feelcrm/Index/Controller/GoogleController.class.php' path, particularly those containing suspicious URL parameters or attempts to access internal IP addresses (e.g., 127.0.0.1, 169.254.169.254).</li>
<li>Monitor for potential exploitation attempts targeting this specific file until an official vendor patch is released.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>ssrf</category></item></channel></rss>