SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.
References
Link Resource
https://github.com/phtcloud-dev/CVE-2024-36837 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2024-06-05T00:00:00

Updated: 2024-06-17T20:46:28.693985

Reserved: 2024-05-30T00:00:00


Link: CVE-2024-36837

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-06-05T15:15:11.803

Modified: 2024-06-18T18:54:51.380


Link: CVE-2024-36837

JSON object: View

cve-icon Redhat Information

No data.

CWE