PT-2024-20962 · Crmeb · Crmeb

Tyaooo

·

Published

2024-02-23

·

Updated

2025-04-25

·

CVE-2024-25469

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CRMEB crmeb java versions 1.3.4 and earlier
Description The issue allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the "api/front/store/list" component. This enables the attacker to exploit the SQL Injection vulnerability, potentially leading to unauthorized access to sensitive data.
Recommendations For CRMEB crmeb java versions 1.3.4 and earlier, consider disabling the "api/front/store/list" component or restricting access to it until a patch is available. Additionally, avoid using the latitude and longitude parameters in this component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-25469

Affected Products

Crmeb