Описание
SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.
SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2024-28714
- https://gitee.com/ZhongBangKeJi/crmeb_java
- https://github.com/JiangXiaoBaiJia/cve2/blob/main/1.md
- https://github.com/JiangXiaoBaiJia/cve2/blob/main/a.png
- https://www.vicarius.io/vsociety/posts/ssti-in-mblog-351-a-tale-of-a-glorified-rce-cve-2024-28713-28714
- http://crmebjava.com
Связанные уязвимости
CVSS3: 8.1
nvd
почти 2 года назад
SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.