CVE-2024-36837
HIGHNuclei
CRMEB v.5.2.2 - SQL Injection
Record summary
CVE-2024-36837 has a selected CVSS score of 7.5 (high); EIP currently links 2 repository PoCs and 1 Nuclei template.
Description
SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
crmebBrowse crmeb / crmebDefault status: unknown | CVE List | 5.2.2 | affected |
Proofs of concept
2Repository PoCs
GitHubphtcloud-dev/CVE-2024-36837Repository PoCby phtcloud-devStars: 3Not analyzed2 files
GitHublhc321-source/CVE-2024-36837Repository PoCby lhc321-sourceStars: 2Not analyzed3 files
Nuclei templates
1ProjectDiscoveryHIGHCRMEB v.5.2.2 - SQL Injection
SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.
Impact
Attackers can execute SQL injection via the selectId parameter in getProductList to obtain sensitive database information.
Remediation
Update CRMEB to a version later than 5.2.2 that patches the SQL injection vulnerability.
AuthorsDhiyaneshDk
Template tagscvecve2024crmebsqlivuln
CPE: cpe:2.3:a:crmeb:crmeb:*:*:*:*:*:*:*:*
FOFA: title="CRMEB"
Source: ProjectDiscovery
References
37nkdkj-my.sharepoint.com
https://7nkdkj-my.sharepoint.com/:w:/g/personal/krypt0n_7nkdkj_onmicrosoft_com/Ea8dW8YuldRMqgCy7KHjnxABTJCVPLShHIJfqQk684mD3A?e=0qmN7t github.com
https://github.com/phtcloud-dev/CVE-2024-36837 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-36837