CVE-2024-25469 Information

Description

SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the api/front/store/list component.

Reference

https://github.com/crmeb/crmeb_java/ https://github.com/crmeb/crmeb_java/issues/20

Share on: