[description]
crmeb <= CRMEB-KY v5.4.0 have sql injection at getRead() in file app/services/system/SystemDatabackupServices.php
[Vulnerability Type]
SQL Injection
[Vendor of Product]
https://www.crmeb.com/
[Affected Product Code Base]
crmeb - <= CRMEB-KY v5.4.0
[Affected Component]
crmeb <= CRMEB-KY v5.4.0 have sql injection at getRead() in file app/services/system/SystemDatabackupServices.php
[Attack Type]
Remote
[Impact Code execution]
true
[Impact Information Disclosure]
true
[Discoverer]
J_0k3r
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view