PT-2026-1189 · Crmeb · Crmeb

·

CVE-2025-15443

·

Published

2026-01-04

·

Updated

2026-01-04

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CRMEB versions prior to 5.6.2
Description A flaw exists in CRMEB that could allow for remote code execution. The issue stems from improper handling of the cate id argument when processing files through the /adminapi/product/product export API endpoint. This can lead to a SQL injection attack. The exploit is publicly available.
Recommendations Update CRMEB to version 5.6.2 or later.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15443

Affected Products

Crmeb