Crmeb Java
Crmeb · 8 CVEs
crmeb crmeb_java base64 Qrcode Endpoint RestTemplateUtil.java RestTemplate.getForEntity server-side request forgery
Jun 3, 2026
crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.…
May 6, 2024
SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via th…
Mar 28, 2024
SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET…
Feb 29, 2024
SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive informa…
Feb 23, 2024
Zhong Bang CRMEB Java save cross site scripting
Mar 23, 2023
Zhong Bang CRMEB Java list getAdminList sql injection
Mar 23, 2023
CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list.
Mar 7, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-10771 | crmeb crmeb_java base64 Qrcode Endpoint RestTemplateUtil.java RestTemplate.getForEntity server-side request forgery | MEDIUM | 0.29% | Jun 3, 2026 |
| CVE-2024-33117 | crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController. | MEDIUM | 0.47% | May 6, 2024 |
| CVE-2024-28714 | SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter. | HIGH | 0.85% | Mar 28, 2024 |
| CVE-2024-24110 | SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spre… | MEDIUM | 0.61% | Feb 29, 2024 |
| CVE-2024-25469 | SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude para… | HIGH | 0.79% | Feb 23, 2024 |
| CVE-2023-1609 | Zhong Bang CRMEB Java save cross site scripting | MEDIUM | 0.52% | Mar 23, 2023 |
| CVE-2023-1608 | Zhong Bang CRMEB Java list getAdminList sql injection | CRITICAL | 0.63% | Mar 23, 2023 |
| CVE-2023-25223 | CRMEB <=1.3.4 is vulnerable to SQL Injection via /api/admin/user/list. | HIGH | 0.76% | Mar 7, 2023 |
Showing 1 to 8 of 8 CVEs