Crmeb

Crmeb

34 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.16%
  • Veröffentlicht 29.06.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 05:12:33

SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php.

Exploit
  • EPSS 0.67%
  • Veröffentlicht 24.06.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 05:12:51

In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file /crmeb/app/admin/controller/store/CopyTaobao.php.

Exploit
  • EPSS 1.85%
  • Veröffentlicht 24.06.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 05:12:51

CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.

Exploit
  • EPSS 2.53%
  • Veröffentlicht 23.10.2020 15:15:12
  • Zuletzt bearbeitet 09.07.2026 00:17:01

A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.