CVE-2023-1165: Zhong Bang CRMEB Java list sql injection
A vulnerability was found in Zhong Bang CRMEB Java 1.3.4. It has been classified as critical. This affects an unknown part of the file /api/admin/system/store/order/list. The manipulation of the argument keywords leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-222261 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1165?
The severity of CVE-2023-1165 is high, with a severity value of 7.2.
What is the affected software for CVE-2023-1165?
The affected software for CVE-2023-1165 is Zhong Bang CRMEB Java version 1.3.4.
How does the vulnerability in CVE-2023-1165 occur?
The vulnerability in CVE-2023-1165 occurs due to a SQL injection in the /api/admin/system/store/order/list endpoint.
Has the exploit for CVE-2023-1165 been disclosed to the public?
Yes, the exploit for CVE-2023-1165 has been disclosed to the public and may be used.
Is there a fix available for CVE-2023-1165?
Yes, a fix for CVE-2023-1165 may be available from the software vendor. Please refer to their official documentation or support channels for more information.