CVE-2025-11290
- EPSS 0.37%
- Veröffentlicht 05.10.2025 11:32:04
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was identified in CRMEB up to 5.6.1. This affects an unknown function of the component JWT HMAC Secret Handler. Such manipulation of the argument secret with the input default leads to use of hard-coded cryptographic key . It is poss...
CVE-2025-11288
- EPSS 0.31%
- Veröffentlicht 05.10.2025 07:32:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi/product/product of the component GET Parameter Handler. Performing a manipulation of the argument cate_id results in sql injectio...
CVE-2025-10391
- EPSS 0.32%
- Veröffentlicht 14.09.2025 05:15:31
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security vulnerability has been detected in CRMEB up to 5.6.1. The impacted element is the function testOutUrl of the file app/services/out/OutAccountServices.php. The manipulation of the argument push_token_url leads to server-side request forgery...
CVE-2025-10390
- EPSS 0.37%
- Veröffentlicht 14.09.2025 04:32:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in CRMEB up to 5.6.1. The affected element is the function editAddress of the file app/services/user/UserAddressServices.php. Executing manipulation of the argument ID can lead to improper authorization. The attack may ...
CVE-2025-10389
- EPSS 0.39%
- Veröffentlicht 14.09.2025 04:15:39
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security flaw has been discovered in CRMEB up to 5.6.1. Impacted is the function Save of the file app/services/system/admin/SystemAdminServices.php of the component Administrator Password Handler. Performing manipulation of the argument ID results ...
CVE-2025-25763
- EPSS 0.91%
- Veröffentlicht 06.03.2025 21:15:15
- Zuletzt bearbeitet 07.07.2025 18:20:03
crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php
CVE-2024-52726
- EPSS 1.63%
- Veröffentlicht 22.11.2024 19:15:07
- Zuletzt bearbeitet 07.07.2025 18:06:25
CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensitive information
CVE-2024-50653
- EPSS 0.51%
- Veröffentlicht 15.11.2024 17:15:20
- Zuletzt bearbeitet 13.03.2025 16:15:24
CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets and sending a large number of data packets for coupon collection, achieving unlimited co...
CVE-2024-6944
- EPSS 3.78%
- Veröffentlicht 21.07.2024 08:15:06
- Zuletzt bearbeitet 03.01.2025 19:11:23
A vulnerability was found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this issue is the function get_image_base64 of the file PublicController.php. The manipulation of the argument file leads to deserialization. The att...
CVE-2024-6943
- EPSS 0.61%
- Veröffentlicht 21.07.2024 07:15:06
- Zuletzt bearbeitet 03.01.2025 19:11:26
A vulnerability has been found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this vulnerability is the function downloadImage of the file app/services/product/product/CopyTaobaoServices.php. The manipulation leads to dese...