CVE-2026-4623General

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in DefaultFuction Jeson-Customer-Relationship-Management-System up to 1b4679c4d06b90d31dd521c2b000bfdec5a36e00. This affects an unknown function of the file /api/System.php of the component API Module. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The identifier of the patch is f76e7123fe093b8675f88ec8f71725b0dd186310/98bd4eb07fa19d4f2c5228de6395580013c97476. It is suggested to install a patch to address this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-24); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-24: 2Mentions · 2026-03-25: 103-2403-25
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-242
Disclosure1General1
2026-03-251
General1
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4623 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4623 #CVE-2026-4623 #CVE #High  #CyberSecurity #InfoSec https://t.co/agguapfAYZ

    Post summary

    A short tweet announces CVE‑2026‑4623 with its severity rating, but provides no PoC, exploit, patch, or detailed technical information.

    0000024
    114 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4623 A security vulnerability has been detected in DefaultFuction Jeson-Customer-Relationship-Management-System up to 1b4679c4d06b90d31dd521c2b000bfdec5a36e00. This affects … https://www.cve.org/CVERecord?id=CVE-2026-4623

    Post summary

    A CVE-2026-4623 vulnerability was noted in the DefaultFuction Jeson-Customer-Relationship-Management-System up to a specific commit; no further details, PoC, or mitigation information are provided.

    00000108
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-4623 - DefaultFuction - Jeson-Customer-Relationship-Management-System - https://www.redpacketsecurity.com/cve-alert-cve-2026-4623-defaultfuction-jeson-customer-relationship-management-system/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4623 #defaultfuction #jeson-customer-relationship-management-system

    Post summary

    A CVE alert for CVE-2026-4623 affecting Jeson‑CRM is posted with a reference link, but no additional exploit, patch, or technical details are provided.

    0000080
    3.6K followersView on X

Explore more