PT-2025-37399 · Crmeb · Crmeb

Yu Bao

·

Published

2025-09-14

·

Updated

2025-10-14

·

CVE-2025-10389

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: CRMEB versions up to 5.6.1
Description: A security flaw exists in CRMEB due to improper authorization when manipulating the ID argument within the Save function of the app/services/system/admin/SystemAdminServices.php file, specifically in the Administrator Password Handler component. This issue may be exploited remotely. The exploit has been publicly released, and the vendor was notified but did not respond.
Recommendations: Versions prior to 5.6.1 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-10389

Affected Products

Crmeb