Zurück zur CVE-Übersicht
CVE-2024-28714
HIGH(8.1)CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Risk Signal Score21/100 — NIEDRIG
- CVSS 8.1 — Hoch
EPSS-Score
1%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
8.1
Technische Schwere
Beschreibung
SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.
Referenzen
- https://gitee.com/ZhongBangKeJi/crmeb_java
- https://github.com/JiangXiaoBaiJia/cve2/blob/main/1.md
- https://github.com/JiangXiaoBaiJia/cve2/blob/main/a.png
- http://crmebjava.com
- https://gitee.com/ZhongBangKeJi/crmeb_java
- https://github.com/JiangXiaoBaiJia/cve2/blob/main/1.md
- https://github.com/JiangXiaoBaiJia/cve2/blob/main/a.png
- https://www.vicarius.io/vsociety/posts/ssti-in-mblog-351-a-tale-of-a-glorified-r...