Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2020-21394

Disclosure Date: June 29, 2021 (last updated February 22, 2025)
SQL Injection vulnerability in Zhong Bang Technology Co., Ltd CRMEB mall system V2.60 and V3.1 via the tablename parameter in SystemDatabackup.php.
Attacker Value
Unknown

CVE-2020-21787

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.
Attacker Value
Unknown

CVE-2020-21788

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file /crmeb/app/admin/controller/store/CopyTaobao.php.