Crmeb

Crmeb

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 01.02.2026 23:32:05
  • Zuletzt bearbeitet 11.02.2026 19:33:06

A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. This vulnerability affects unknown code of the file crmeb/app/api/controller/v1/CrontabController.php of the component crontab Endpoint. The manipulation results in missing authoriz...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 01.02.2026 23:15:49
  • Zuletzt bearbeitet 11.02.2026 19:32:34

A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. This affects the function detail/tidyOrder of the file /api/store_integral/order/detail/:uni. The manipulation of the argument order_id leads to improper authorization. The attack can be...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 20.01.2026 01:15:56
  • Zuletzt bearbeitet 29.01.2026 21:14:38

A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crmeb/app/services/user/LoginServices.php of the component JSON Token Handler. Executing a manipulation of the argument uid can lead ...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 20.01.2026 01:15:56
  • Zuletzt bearbeitet 29.01.2026 21:16:18

A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/LoginController.php. Performing a manipulation of the argument openId results in improper authentication...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 04.01.2026 11:32:06
  • Zuletzt bearbeitet 14.01.2026 20:30:27

A vulnerability was identified in CRMEB up to 5.6.1. This issue affects some unknown processing of the file /adminapi/product/product_export. Such manipulation of the argument cate_id leads to sql injection. The attack may be launched remotely. The e...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 04.01.2026 11:15:53
  • Zuletzt bearbeitet 13.01.2026 20:46:47

A vulnerability was determined in CRMEB up to 5.6.1. This vulnerability affects unknown code of the file /adminapi/export/product_list. This manipulation of the argument cate_id causes sql injection. The attack may be initiated remotely. The exploit ...

  • EPSS 0.03%
  • Veröffentlicht 05.10.2025 11:32:04
  • Zuletzt bearbeitet 07.10.2025 17:28:32

A vulnerability was identified in CRMEB up to 5.6.1. This affects an unknown function of the component JWT HMAC Secret Handler. Such manipulation of the argument secret with the input default leads to use of hard-coded cryptographic key . It is poss...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 05.10.2025 07:32:06
  • Zuletzt bearbeitet 24.02.2026 07:16:22

A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi/product/product of the component GET Parameter Handler. Performing a manipulation of the argument cate_id results in sql injectio...

  • EPSS 0.05%
  • Veröffentlicht 14.09.2025 05:15:31
  • Zuletzt bearbeitet 14.10.2025 19:11:12

A security vulnerability has been detected in CRMEB up to 5.6.1. The impacted element is the function testOutUrl of the file app/services/out/OutAccountServices.php. The manipulation of the argument push_token_url leads to server-side request forgery...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 14.09.2025 04:32:05
  • Zuletzt bearbeitet 14.10.2025 19:22:48

A weakness has been identified in CRMEB up to 5.6.1. The affected element is the function editAddress of the file app/services/user/UserAddressServices.php. Executing manipulation of the argument ID can lead to improper authorization. The attack may ...