VendorsCRMEBcrmeb_javaall versions
Vulnerabilities

CRMEB Java

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2023-1608
Zhong Bang CRMEB Java list getAdminList sql injection
Published 2023-03-23 · Modified
9.8EPSS 0.006
CVE-2024-28714
SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.
Published 2024-03-28 · Modified
8.1EPSS 0.008
CVE-2024-25469
SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the api/front/store/list component.
Published 2024-02-23 · Analyzed
7.5EPSS 0.008
CVE-2023-25223
CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list.
Published 2023-03-07 · Modified
7.2EPSS 0.008
CVE-2024-24110
SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spread/people.
Published 2024-02-29 · Analyzed
6.5EPSS 0.006
CVE-2023-1609
Zhong Bang CRMEB Java save cross site scripting
Published 2023-03-23 · Modified
5.4EPSS 0.005
CVE-2024-33117
crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController.
Published 2024-05-06 · Analyzed
5.3EPSS 0.005