📦 Crmeb Java

by Crmeb

🔍 What is Crmeb Java?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-28714

HIGH CVSS 8.1 Mar 28, 2024

This SQL injection vulnerability in CRMEB_Java e-commerce system allows attackers to execute arbitrary SQL commands via the groupid parameter. Attackers can potentially read, modify, or delete databas...

CVE-2024-25469

HIGH CVSS 7.5 Feb 23, 2024

This SQL injection vulnerability in CRMEB Java versions 1.3.4 and earlier allows remote attackers to extract sensitive database information by manipulating latitude and longitude parameters in the sto...

CVE-2023-25223

HIGH CVSS 7.2 Mar 7, 2023

CRMEB versions up to 1.3.4 contain a SQL injection vulnerability in the admin user list API endpoint. Attackers can execute arbitrary SQL commands through the /api/admin/user/list endpoint, potentiall...

CVE-2024-33117

MEDIUM CVSS 5.3 May 6, 2024

CVE-2024-33117 is a Server-Side Request Forgery (SSRF) vulnerability in crmeb_java v1.3.4 that allows attackers to make the server send unauthorized requests to internal systems. This affects any depl...

CVE-2023-1608

MEDIUM CVSS 6.3 Mar 23, 2023

This is a critical SQL injection vulnerability in Zhong Bang CRMEB Java software that allows remote attackers to execute arbitrary SQL commands by manipulating the cateId parameter in the getAdminList...