CVE-2024-36837
- EPSS 8.31%
- Veröffentlicht 05.06.2024 15:15:11
- Zuletzt bearbeitet 21.11.2024 09:22:41
SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.
CVE-2024-1704
- EPSS 0.65%
- Veröffentlicht 21.02.2024 18:15:50
- Zuletzt bearbeitet 03.01.2025 19:11:28
A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been declared as critical. This vulnerability affects the function save/delete of the file /adminapi/system/crud. The manipulation leads to path traversal. The exploit has been disclosed ...
CVE-2024-1703
- EPSS 0.71%
- Veröffentlicht 21.02.2024 17:15:08
- Zuletzt bearbeitet 03.01.2025 19:11:33
A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function openfile of the file /adminapi/system/file/openfile. The manipulation leads to absolute path traversal. The exploit has been disc...
CVE-2023-3233
- EPSS 0.82%
- Veröffentlicht 14.06.2023 07:15:09
- Zuletzt bearbeitet 21.11.2024 08:16:45
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been classified as critical. Affected is the function get_image_base64 of the file api/controller/v1/PublicController.php. The manipulation leads to server-side request forgery. It is ...
CVE-2023-3234
- EPSS 1.17%
- Veröffentlicht 14.06.2023 07:15:09
- Zuletzt bearbeitet 21.11.2024 08:16:45
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been declared as problematic. Affected by this vulnerability is the function put_image of the file api/controller/v1/PublicController.php. The manipulation leads to deserialization. Th...
CVE-2023-3232
- EPSS 1.2%
- Veröffentlicht 14.06.2023 06:15:09
- Zuletzt bearbeitet 21.11.2024 08:16:45
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. This issue affects some unknown processing of the file /api/wechat/app_auth of the component Image Upload. The manipulation leads to deserialization. The exploit ha...
CVE-2023-30185
- EPSS 1.11%
- Veröffentlicht 08.05.2023 01:15:08
- Zuletzt bearbeitet 09.07.2026 01:18:16
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.
CVE-2023-2419
- EPSS 0.82%
- Veröffentlicht 29.04.2023 01:15:09
- Zuletzt bearbeitet 21.11.2024 07:58:34
A vulnerability was found in Zhong Bang CRMEB 4.6.0. It has been declared as critical. This vulnerability affects the function videoUpload of the file \crmeb\app\services\system\attachment\SystemAttachmentServices.php. The manipulation of the argumen...
CVE-2023-1165
- EPSS 0.76%
- Veröffentlicht 03.03.2023 08:15:12
- Zuletzt bearbeitet 21.11.2024 07:38:35
A vulnerability was found in Zhong Bang CRMEB Java 1.3.4. It has been classified as critical. This affects an unknown part of the file /api/admin/system/store/order/list. The manipulation of the argument keywords leads to sql injection. The exploit h...
CVE-2022-44343
- EPSS 0.64%
- Veröffentlicht 06.02.2023 14:15:09
- Zuletzt bearbeitet 26.03.2025 15:15:40
CRMEB 4.4.4 is vulnerable to Any File download.