PT-2020-16089 · Crmeb · Crmeb

Viktorwkxstar

·

Published

2020-10-23

·

Updated

2020-10-27

·

CVE-2020-25466

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CRMEB version 3.0
Description A SSRF issue exists in the downloadimage interface, allowing remote download of arbitrary files on the server and potentially enabling remote execution of arbitrary code.
Recommendations For CRMEB version 3.0, consider restricting access to the downloadimage interface as a temporary workaround until a patch is available.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25466

Affected Products

Crmeb