Deserialization Vulnerability in ZhongBangKeJi CRMEB
CVE-2024-6943
What is CVE-2024-6943?
A critical security vulnerability has been identified in the CRMEB application developed by Xi'an Zhongbang Network Technology Co. This vulnerability affects versions up to 5.4.0, specifically in the downloadImage function located in the CopyTaobaoServices.php file. Exploiting this vulnerability allows an attacker to manipulate the deserialization process, which can lead to remote code execution (RCE). The vulnerability is publicly known and poses significant risks as attackers can execute malicious code from a remote location. The vendor has not responded to existing notifications regarding this issue, further emphasizing the need for immediate attention from users and administrators of affected systems to implement necessary security measures.
Affected Version(s)
CRMEB 5.0
CRMEB 5.1
CRMEB 5.2
