Crmeb

Crmeb Java

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 03.06.2026 22:16:34
  • Zuletzt bearbeitet 04.06.2026 16:37:27

A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the component base64 Qrcode Endpoint. The manipulation of the ...

  • EPSS 0.34%
  • Veröffentlicht 17.03.2025 07:15:33
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4. Affected by this issue is the function webHook of the file WeChatMessageController.java. The manipulation leads to xml external entity reference. The atta...

  • EPSS 0.47%
  • Veröffentlicht 06.05.2024 20:15:10
  • Zuletzt bearbeitet 11.06.2025 12:04:14

crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController.

Exploit
  • EPSS 0.84%
  • Veröffentlicht 28.03.2024 23:15:46
  • Zuletzt bearbeitet 10.06.2025 00:54:10

SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.

Exploit
  • EPSS 0.61%
  • Veröffentlicht 21.03.2024 02:52:09
  • Zuletzt bearbeitet 10.06.2025 15:50:19

SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spread/people.

Exploit
  • EPSS 0.79%
  • Veröffentlicht 23.02.2024 23:15:09
  • Zuletzt bearbeitet 25.04.2025 19:37:07

SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the api/front/store/list component.

Exploit
  • EPSS 0.63%
  • Veröffentlicht 23.03.2023 20:15:14
  • Zuletzt bearbeitet 21.11.2024 07:39:31

A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been declared as critical. This vulnerability affects the function getAdminList of the file /api/admin/store/product/list. The manipulation of the argument cateId leads to sql inj...

Exploit
  • EPSS 0.52%
  • Veröffentlicht 23.03.2023 20:15:14
  • Zuletzt bearbeitet 21.11.2024 07:39:31

A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been rated as problematic. This issue affects the function save of the file /api/admin/store/product/save. The manipulation leads to cross site scripting. The attack may be initia...

Exploit
  • EPSS 0.76%
  • Veröffentlicht 07.03.2023 17:15:12
  • Zuletzt bearbeitet 05.03.2025 16:15:36

CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list.