CVE-2026-86171 | DefaultFuction CRM 1.0.0 delete.php ID sql injection (EUVD-2026-72067 / CNNVD-2026-96350555)
A vulnerability classified as critical was found in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql injection.
This vulnerability is listed as CVE-2026-86171. The attack may be performed from remote. In addition, an exploit is available.