CVE-2024-36837

HIGH NUCLEI

CRMEB <5.2.2 - SQL Injection

Title source: llm

Description

SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.

Exploits (2)

nomisec SCANNER 4 stars
by phtcloud-dev · poc
https://github.com/phtcloud-dev/CVE-2024-36837
nomisec WORKING POC 2 stars
by lhc321-source · poc
https://github.com/lhc321-source/CVE-2024-36837

Nuclei Templates (1)

CRMEB v.5.2.2 - SQL Injection
HIGHVERIFIEDby DhiyaneshDk
FOFA: title="CRMEB"

Scores

CVSS v3 7.5
EPSS 0.9166
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-89
Status published
Products (1)
crmeb/crmeb 5.2.2
Published Jun 05, 2024
Tracked Since Feb 18, 2026