Vulnerabilities (CVE)

Filtered by vendor Crmeb Subscribe
Filtered by product Crmeb
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-21787 1 Crmeb 1 Crmeb 2021-06-30 10.0 HIGH 9.8 CRITICAL
CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.
CVE-2020-25466 1 Crmeb 1 Crmeb 2020-10-27 7.5 HIGH 9.8 CRITICAL
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.