← Back

Crmeb

crmeb

Vendor: Crmeb • 30 CVEs

CVEs (30)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Crmeb
1Crmeb
Nov 21, 2024
Jun 14, 2023
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been classified as critical. Affected is the function get_image_base64 of the file api/controller/v1/PublicController.php. The manipulation leads to serve...Show more
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been classified as critical. Affected is the function get_image_base64 of the file api/controller/v1/PublicController.php. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231504. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Crmeb
1Crmeb
Nov 21, 2024
Jun 14, 2023
N/A· v4
9.8 CRITICAL· v3
5.8 MEDIUM· v2
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. This issue affects some unknown processing of the file /api/wechat/app_auth of the component Image Upload. The manipulation leads to d...Show more
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. This issue affects some unknown processing of the file /api/wechat/app_auth of the component Image Upload. The manipulation leads to deserialization. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-231503. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Crmeb
1Crmeb
Jan 29, 2025
May 8, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.
1Crmeb
1Crmeb
Nov 21, 2024
Apr 29, 2023
N/A· v4
7.2 HIGH· v3
5.8 MEDIUM· v2
A vulnerability was found in Zhong Bang CRMEB 4.6.0. It has been declared as critical. This vulnerability affects the function videoUpload of the file \crmeb\app\services\system\attachment\SystemAttachmentServices.php. T...Show more
A vulnerability was found in Zhong Bang CRMEB 4.6.0. It has been declared as critical. This vulnerability affects the function videoUpload of the file \crmeb\app\services\system\attachment\SystemAttachmentServices.php. The manipulation of the argument filename leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-227716.Show less
1Crmeb
1Crmeb
Nov 21, 2024
Mar 3, 2023
N/A· v4
7.2 HIGH· v3
5.2 MEDIUM· v2
A vulnerability was found in Zhong Bang CRMEB Java 1.3.4. It has been classified as critical. This affects an unknown part of the file /api/admin/system/store/order/list. The manipulation of the argument keywords leads t...Show more
A vulnerability was found in Zhong Bang CRMEB Java 1.3.4. It has been classified as critical. This affects an unknown part of the file /api/admin/system/store/order/list. The manipulation of the argument keywords leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-222261 was assigned to this vulnerability.Show less
1Crmeb
1Crmeb
Mar 26, 2025
Feb 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
CRMEB 4.4.4 is vulnerable to Any File download.
1Crmeb
1Crmeb
Nov 21, 2024
Jun 29, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php.
1Crmeb
1Crmeb
Nov 21, 2024
Jun 24, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file /crmeb/app/admin/controller/store/CopyTaobao.php.
1Crmeb
1Crmeb
Nov 21, 2024
Jun 24, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.
1Crmeb
1Crmeb
Nov 21, 2024
Oct 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.