CVE-2026-79425
- EPSS 0.33%
- Veröffentlicht 15.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 20:00:03
An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows attackers to scan internal resources via a crafted POST request.
CVE-2026-79426
- EPSS 0.15%
- Veröffentlicht 04.09.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 16:04:24
An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request.
CVE-2026-85212
- EPSS 0.33%
- Veröffentlicht 03.09.2026 14:12:23
- Zuletzt bearbeitet 10.09.2026 15:53:23
CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploi...
CVE-2026-85177
- EPSS 0.22%
- Veröffentlicht 03.09.2026 14:12:16
- Zuletzt bearbeitet 23.09.2026 17:17:45
CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system inbox messages. Attackers can update any message's columns including is_del, l...
CVE-2026-1734
- EPSS 0.47%
- Veröffentlicht 01.02.2026 23:32:05
- Zuletzt bearbeitet 11.02.2026 19:33:06
A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. This vulnerability affects unknown code of the file crmeb/app/api/controller/v1/CrontabController.php of the component crontab Endpoint. The manipulation results in missing authoriz...
CVE-2026-1733
- EPSS 0.36%
- Veröffentlicht 01.02.2026 23:15:49
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. This affects the function detail/tidyOrder of the file /api/store_integral/order/detail/:uni. The manipulation of the argument order_id leads to improper authorization. The attack can be...
CVE-2026-1202
- EPSS 0.8%
- Veröffentlicht 20.01.2026 01:15:56
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/LoginController.php. Performing a manipulation of the argument openId results in improper authentication...
CVE-2026-1203
- EPSS 0.73%
- Veröffentlicht 20.01.2026 01:15:56
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crmeb/app/services/user/LoginServices.php of the component JSON Token Handler. Executing a manipulation of the argument uid can lead ...
CVE-2025-15443
- EPSS 0.33%
- Veröffentlicht 04.01.2026 11:32:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was identified in CRMEB up to 5.6.1. This issue affects some unknown processing of the file /adminapi/product/product_export. Such manipulation of the argument cate_id leads to sql injection. The attack may be launched remotely. The e...
CVE-2025-15442
- EPSS 0.33%
- Veröffentlicht 04.01.2026 11:15:53
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was determined in CRMEB up to 5.6.1. This vulnerability affects unknown code of the file /adminapi/export/product_list. This manipulation of the argument cate_id causes sql injection. The attack may be initiated remotely. The exploit ...