Zhong Bang Technology Co. · Crmeb Mall System · CVE-2020-21394
Name of the Vulnerable Software and Affected Versions:
Zhong Bang Technology Co., Ltd CRMEB mall system versions 2.60 through 3.1
Description:
The issue is related to a SQL Injection vulnerability. It can be exploited via the `tablename` parameter in the SystemDatabackup.php file.
Recommendations:
For versions 2.60 through 3.1, avoid using the `tablename` parameter in the SystemDatabackup.php file until a fix is available. Restrict access to the SystemDatabackup.php file to minimize the risk of exploitation.