Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.8
CVE-2020-21394
- EPSS 1.16%
- Veröffentlicht 29.06.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:33
SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php.
4.3
CVE-2020-21788
- EPSS 0.67%
- Veröffentlicht 24.06.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:12:51
In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file /crmeb/app/admin/controller/store/CopyTaobao.php.
- EPSS 1.85%
- Veröffentlicht 24.06.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:12:51
CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.
9.8
CVE-2020-25466
- EPSS 2.53%
- Veröffentlicht 23.10.2020 15:15:12
- Zuletzt bearbeitet 09.07.2026 00:17:01
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.