A vulnerability was found in Zhong Bang CRMEB 4.6.0. It has been declared as critical. This vulnerability affects the function videoUpload of the file \crmeb\app\services\system\attachment\SystemAttachmentServices.php. The manipulation of the argument filename leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-227716.
References
Link Resource
https://github.com/crmeb/CRMEB/issues/77 Exploit
https://vuldb.com/?ctiid.227716 Permissions Required
https://vuldb.com/?id.227716 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: VulDB

Published: 2023-04-29T01:00:06.164Z

Updated: 2023-10-22T19:10:52.942Z

Reserved: 2023-04-28T16:56:37.249Z


Link: CVE-2023-2419

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-04-29T01:15:09.063

Modified: 2024-05-17T02:22:58.180


Link: CVE-2023-2419

JSON object: View

cve-icon Redhat Information

No data.

CWE