CVE-2026-10771

HIGH

crmeb crmeb_java base64 Qrcode Endpoint RestTemplateUtil.java RestTemplate.getForEntity server-side request forgery

Title source: cna
STIX 2.1

Description

A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the component base64 Qrcode Endpoint. The manipulation of the argument url results in server-side request forgery. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-368137 | crmeb crmeb_java base64 Qrcode Endpoint RestTemplateUtil.java RestTemplate.getForEntity server-side request forgery
https://vuldb.com/vuln/368137
Signature, Permissions Required signature permissions-required
VDB-368137 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/368137/cti
Third Party Advisory third-party-advisory
CVE-2026-10771 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-10771
Third Party Advisory third-party-advisory
Submit #831421 | https://github.com/crmeb/crmeb_java crmeb_java v1.4 Server -Side Request Forgery
https://vuldb.com/submit/831421
Exploit exploit issue-tracking
https://github.com/crmeb/crmeb_java/issues/35

Scores

CVSS v3 7.3
EPSS 0.0029
EPSS Percentile 20.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
crmeb/crmeb_java 1.4
Published Jun 03, 2026
Tracked Since Jun 04, 2026