CVE-2023-1165

CVSS V2 None CVSS V3 None
Description
A vulnerability was found in Zhong Bang CRMEB Java 1.3.4. It has been classified as critical. This affects an unknown part of the file /api/admin/system/store/order/list. The manipulation of the argument keywords leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-222261 was assigned to this vulnerability.
Overview
  • CVE ID
  • CVE-2023-1165
  • Assigner
  • cna@vuldb.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-03T08:15:12
  • Last Modified Date
  • 2023-03-10T19:07:25
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:crmeb:crmeb:1.3.4:*:*:*:*:java:*:* 1 OR
References
Reference URL Reference Tags
https://github.com/ha1yuYiqiyinHangzhouTechn0logy/crmeb_java/blob/main/README.md Exploit Third Party Advisory
https://vuldb.com/?ctiid.222261 Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?id.222261 Third Party Advisory VDB Entry
History
Created Old Value New Value Data Type Notes
2023-04-17 05:53:29 Added to TrackCVE
2023-04-17 05:53:31 Weakness Enumeration new