CVE-2021-48008 Overview
CVE-2021-48008 is an unauthenticated SQL injection vulnerability [CWE-89] in Chanjet CRM. The flaw resides in the webservice endpoint, where the site_id GET parameter is passed to database queries without sanitization or parameterization. Remote attackers can execute arbitrary SQL queries against the underlying database using UNION-based injection techniques to extract sensitive records. No authentication is required to exploit the endpoint. The Shadowserver Foundation first observed exploitation evidence on 2023-10-18, and public detection templates for the flaw exist in the Nuclei project.
Critical Impact
Unauthenticated remote attackers can extract confidential data from the Chanjet CRM database by supplying crafted SQL payloads in the site_id GET parameter.
Affected Products
- Chanjet CRM (webservice endpoint)
- Chanjet T-Plus product family referenced in the Nuclei template path chanjet-tplus
- Deployments tracked under advisory CNVD-2021-12845
Discovery Timeline
- 2026-09-18 - CVE-2021-48008 published to NVD
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2021-48008
Vulnerability Analysis
The vulnerability is a classic SQL injection [CWE-89] within the Chanjet CRM webservice HTTP endpoint. The application concatenates the user-supplied site_id query string parameter directly into a backend SQL statement. Because the value is neither escaped nor bound as a parameter, an attacker can terminate the intended clause and append additional SQL syntax. UNION-based payloads let the attacker read arbitrary columns from other tables the database user can access. The VulnCheck advisory documents the flaw in the GetUsedSpace.php handler, indicating the sink is reached through a standard HTTP GET request.
Root Cause
The root cause is missing input validation and the absence of prepared statements in the code path that handles the site_id parameter. The parameter is trusted as an integer identifier but never validated as such before being used in a raw SQL query.
Attack Vector
Exploitation is network-based and requires no privileges or user interaction. An attacker issues a single HTTP GET request to the webservice endpoint with a crafted site_id value containing SQL syntax. Community tooling automates the identification and exploitation of the flaw. The public Nuclei template provides a reproducible detection pattern that mirrors a working exploit request.
// No verified proof-of-concept code is published in the referenced advisories.
// See the Nuclei template linked above for the exact request signature used
// for detection and validation of the injection point in the site_id parameter.
Detection Methods for CVE-2021-48008
Indicators of Compromise
- HTTP GET requests to the Chanjet webservice endpoint or GetUsedSpace.php containing SQL keywords such as UNION, SELECT, SLEEP, or -- in the site_id parameter.
- Unusual outbound database responses or oversized response bodies from the CRM host correlated with site_id requests from a single source IP.
- Web server access log entries showing URL-encoded characters (%27, %20, %2C) inside the site_id value.
Detection Strategies
- Deploy the ProjectDiscovery Nuclei template for Chanjet CRM SQLi against internet-facing assets to identify vulnerable instances.
- Add web application firewall (WAF) signatures that flag SQL metacharacters in the site_id parameter and any request to the webservice path.
- Correlate access logs with database audit logs to detect queries containing multi-statement UNION SELECT constructs originating from the CRM service account.
Monitoring Recommendations
- Enable full HTTP request logging on the Chanjet CRM reverse proxy or IIS front end to preserve full query strings.
- Alert on repeated 500-status responses from the webservice endpoint, which often indicate injection probing.
- Monitor the CRM database user for unexpected information_schema or sysobjects access patterns.
How to Mitigate CVE-2021-48008
Immediate Actions Required
- Restrict network access to the Chanjet CRM webservice endpoint to trusted internal ranges until a vendor fix is applied.
- Deploy a WAF rule that rejects any site_id value that is not a strictly numeric identifier.
- Review database and web server logs since 2023-10-18 for the injection indicators listed above, given documented in-the-wild exploitation reported by the Shadowserver Foundation.
Patch Information
No vendor patch URL is included in the referenced advisories. Consult the Chanjet official website and the CNVD-2021-12845 entry for the latest vendor guidance and upgrade instructions. Additional technical context is available in the VulnCheck SQL Injection Advisory.
Workarounds
- Place the CRM behind an authenticated reverse proxy so that the webservice endpoint cannot be reached anonymously from the internet.
- Configure the database account used by Chanjet CRM with least-privilege access so UNION-based extraction returns no cross-table data.
- Terminate the affected endpoint at a WAF that enforces integer-only validation on site_id and blocks SQL metacharacters.
# Example nginx snippet to reject non-numeric site_id values before they reach the app
location ~* /webservice {
if ($arg_site_id !~ '^[0-9]+$') {
return 400;
}
proxy_pass http://chanjet_backend;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.