Deserialization Vulnerability in ZhongBangKeJi CRMEB
CVE-2024-6943

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
21 July 2024

Badges

👾 Exploit Exists

What is CVE-2024-6943?

A critical security vulnerability has been identified in the CRMEB application developed by Xi'an Zhongbang Network Technology Co. This vulnerability affects versions up to 5.4.0, specifically in the downloadImage function located in the CopyTaobaoServices.php file. Exploiting this vulnerability allows an attacker to manipulate the deserialization process, which can lead to remote code execution (RCE). The vulnerability is publicly known and poses significant risks as attackers can execute malicious code from a remote location. The vendor has not responded to existing notifications regarding this issue, further emphasizing the need for immediate attention from users and administrators of affected systems to implement necessary security measures.

Affected Version(s)

CRMEB 5.0

CRMEB 5.1

CRMEB 5.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

J1rrY (VulDB User)
.