CVE-2023-3233
- EPSS 0.06%
- Veröffentlicht 14.06.2023 07:15:09
- Zuletzt bearbeitet 21.11.2024 08:16:45
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been classified as critical. Affected is the function get_image_base64 of the file api/controller/v1/PublicController.php. The manipulation leads to server-side request forgery. It is ...
CVE-2023-3232
- EPSS 0.08%
- Veröffentlicht 14.06.2023 06:15:09
- Zuletzt bearbeitet 21.11.2024 08:16:45
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. This issue affects some unknown processing of the file /api/wechat/app_auth of the component Image Upload. The manipulation leads to deserialization. The exploit ha...
CVE-2023-30185
- EPSS 0.64%
- Veröffentlicht 08.05.2023 01:15:08
- Zuletzt bearbeitet 29.01.2025 21:15:18
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.
CVE-2023-2419
- EPSS 0.08%
- Veröffentlicht 29.04.2023 01:15:09
- Zuletzt bearbeitet 21.11.2024 07:58:34
A vulnerability was found in Zhong Bang CRMEB 4.6.0. It has been declared as critical. This vulnerability affects the function videoUpload of the file \crmeb\app\services\system\attachment\SystemAttachmentServices.php. The manipulation of the argumen...
CVE-2023-1165
- EPSS 0.33%
- Veröffentlicht 03.03.2023 08:15:12
- Zuletzt bearbeitet 21.11.2024 07:38:35
A vulnerability was found in Zhong Bang CRMEB Java 1.3.4. It has been classified as critical. This affects an unknown part of the file /api/admin/system/store/order/list. The manipulation of the argument keywords leads to sql injection. The exploit h...
CVE-2022-44343
- EPSS 0.32%
- Veröffentlicht 06.02.2023 14:15:09
- Zuletzt bearbeitet 26.03.2025 15:15:40
CRMEB 4.4.4 is vulnerable to Any File download.
CVE-2020-21394
- EPSS 0.26%
- Veröffentlicht 29.06.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:33
SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php.
CVE-2020-21788
- EPSS 0.14%
- Veröffentlicht 24.06.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:12:51
In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file /crmeb/app/admin/controller/store/CopyTaobao.php.
- EPSS 0.4%
- Veröffentlicht 24.06.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:12:51
CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.
CVE-2020-25466
- EPSS 1.31%
- Veröffentlicht 23.10.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:00
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.