THREAT OPS › Threat News › [NVD] CVE-2026-86172 (MEDIUM 6.3) — A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public a
[NVD] CVE-2026-86172 (MEDIUM 6.3) — A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public a
CVE-2026-86172 CVSS: 6.3 MEDIUM Published: 2026-09-06T08:16:40.760
A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Indicators of compromise
- CVE-2026-86172cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86172