CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensitive information
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/sec-Kode/cve3/blob/main/cve3.md | broken link |
https://gist.github.com/sec-Kode/bb71138619b22de28c6b0ba986ad58e5 | third party advisory |