CVE-2026-84111 Overview
CVE-2026-84111 is a SQL injection vulnerability in Chanjet CRM versions up to 20260707. The flaw resides in the jxf_dump_table.php script, where the gblOrgID parameter is passed to database queries without proper sanitization. Remote attackers can manipulate this parameter to inject arbitrary SQL statements. The vulnerability has been publicly disclosed, and a proof-of-concept exploit is available. According to the disclosure, the vendor was contacted early but did not respond. This weakness is categorized under CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component.
Critical Impact
Unauthenticated remote attackers can inject SQL statements through the gblOrgID parameter, exposing CRM database contents to disclosure, modification, or destruction.
Affected Products
- Chanjet CRM versions up to and including 20260707
- Deployments exposing jxf_dump_table.php to untrusted networks
- Any downstream integration relying on the affected CRM database
Discovery Timeline
- 2026-09-01 - CVE-2026-84111 published to the National Vulnerability Database (NVD)
- 2026-09-01 - Last updated in NVD database
Technical Details for CVE-2026-84111
Vulnerability Analysis
The vulnerability is a classic SQL injection flaw in the jxf_dump_table.php endpoint of Chanjet CRM. The gblOrgID request argument is concatenated into a SQL query without parameterization or input validation. An attacker can supply crafted input that alters the structure of the underlying query. Because the endpoint is remotely reachable and requires no authentication, exploitation can be automated with common tooling such as sqlmap. Successful exploitation can expose CRM records, credential material, and configuration data stored in the backing database.
Root Cause
The root cause is improper neutralization of user-supplied input placed into SQL statements [CWE-74]. The gblOrgID parameter received by jxf_dump_table.php is not bound as a prepared-statement parameter and is not filtered against a strict allowlist. Any special SQL metacharacter reaching the query builder becomes part of the executed statement.
Attack Vector
Exploitation occurs over the network against a reachable Chanjet CRM instance. The attacker sends an HTTP request to jxf_dump_table.php with a manipulated gblOrgID value containing SQL syntax. No user interaction and no valid credentials are required. Once the injection succeeds, standard SQL injection techniques such as UNION-based extraction, boolean-based blind inference, or time-based blind inference can be applied to read or modify database contents. Public disclosure references, including the GitHub issue for CVE-2026-84111 and the VulDB entry for CVE-2026-84111, describe the exposed parameter and endpoint. No verified proof-of-concept code is reproduced here; refer to the linked advisories for technical detail.
Detection Methods for CVE-2026-84111
Indicators of Compromise
- HTTP requests to jxf_dump_table.php containing SQL metacharacters such as single quotes, UNION, SELECT, SLEEP(, or comment sequences in the gblOrgID parameter.
- Unexpected SELECT, UNION, or INFORMATION_SCHEMA queries in database logs originating from the CRM application account.
- Elevated response-time variance on requests to jxf_dump_table.php, consistent with time-based blind injection.
- Web server logs showing repeated gblOrgID values from a single source IP with encoded payloads.
Detection Strategies
- Deploy web application firewall (WAF) signatures that flag SQL syntax in the gblOrgID query-string and POST parameter.
- Enable database query logging and alert on queries referencing INFORMATION_SCHEMA, sysobjects, or long UNION chains from the CRM service account.
- Correlate web access logs with database logs to identify parameter-to-query causal chains that indicate injection attempts.
Monitoring Recommendations
- Baseline normal query patterns from the CRM application and alert on statistical deviations in query length or table access.
- Monitor egress from the CRM host for unusual bulk data transfers that may indicate database exfiltration.
- Review authentication and file-write activity on the CRM host, since SQL injection can escalate to file writes or credential theft depending on database privileges.
How to Mitigate CVE-2026-84111
Immediate Actions Required
- Restrict network access to jxf_dump_table.php using firewall rules or reverse-proxy allowlists until a fix is applied.
- Place the CRM behind a WAF with SQL injection rules tuned for the gblOrgID parameter.
- Rotate database credentials used by the CRM if injection attempts are observed in logs.
- Reduce the privileges of the database account used by Chanjet CRM to the minimum required.
Patch Information
No vendor patch has been published at the time of writing. The disclosure notes that the vendor was contacted but did not respond. Track the VulDB entry for CVE-2026-84111 and the public GitHub disclosure for updates. Until an official fix ships, apply the compensating controls listed above.
Workarounds
- Block or filter requests to jxf_dump_table.php at the reverse proxy where the endpoint is not required.
- Enforce a strict numeric allowlist for the gblOrgID parameter using WAF rules or an inline request filter.
- Segment the CRM database on a dedicated network and disable outbound internet access from the database host.
- Enable verbose query auditing on the CRM database to support incident response if injection is attempted.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.