VendorsCRMEBcrmeb_java1.3.4
Vulnerabilities

CRMEB Java 1.3.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2024-25469
SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the api/front/store/list component.
Published 2024-02-23 · Analyzed
7.5EPSS 0.008
CVE-2024-33117
crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController.
Published 2024-05-06 · Analyzed
5.3EPSS 0.005