A SQL injection vulnerability has been discovered in Chanjet CRM versions up to 20260707. The flaw exists in the file jxf_dump_table.php, where manipulation of the argument gblOrgID allows SQL injection attacks. The vulnerability can be exploited remotely, making it accessible to a wide range of attackers. A public exploit has already been published and is available for use. The vendor was notified early in the disclosure process but failed to respond, leaving users without an official patch or mitigation. This unpatched state combined with a public exploit significantly increases the risk of exploitation in the wild.