CVE-2026-86170 | DefaultFuction CRM 1.0.0 /modules/orders/edit.php ID sql injection (EUVD-2026-72059)
A vulnerability classified as critical has been found in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes sql injection.
This vulnerability is tracked as CVE-2026-86170. The attack is possible to be carried out remotely. Moreover, an exploit is present.