A vulnerability has been found in ZhongBangKeJi CRMEB up to 5.4.0 and classified as critical. Affected by this vulnerability is the function downloadImage of the file app/services/product/product/CopyTaobaoServices.php. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272065 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://vuldb.com/?id.272065 | vdb entry permissions required technical description |
https://vuldb.com/?ctiid.272065 | signature permissions required |
https://vuldb.com/?submit.374394 | third party advisory |
https://gist.github.com/J1rrY-learn/e15a1926a3b5a2b8805a15cb95eff1d7 | broken link exploit |