Improper Authorization in CRMEB Affects User Address Management
CVE-2025-10390
Key Information:
Badges
What is CVE-2025-10390?
A vulnerability has been identified in CRMEB versions up to 5.6.1 affecting the function editAddress in app/services/user/UserAddressServices.php. This issue arises when an attacker manipulates the argument ID, potentially leading to unauthorized actions. The exploit can be executed remotely, making it a significant risk for users. Despite efforts to inform the vendor about this critical weakness, there has been no response regarding remediation or security updates.
Affected Version(s)
CRMEB 5.6.0
CRMEB 5.6.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved