A SQL injection vulnerability has been identified in Chanjet CRM versions up to 20260707. The flaw exists in the file jxf_dump_table.php, where manipulation of the gblOrgID argument allows for SQL injection attacks. Remote exploitation is possible, making this a significant risk for affected deployments. A public exploit has been published and is available for use by threat actors. The vendor was notified prior to disclosure but did not respond, leaving users without an official patch or mitigation. This unpatched status, combined with public exploit availability, raises the severity of the issue considerably. Organizations using Chanjet CRM should take immediate precautionary measures to limit exposure.