CVE-2023-1608: Zhong Bang CRMEB Java list getAdminList sql injection
A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been declared as critical. This vulnerability affects the function getAdminList of the file /api/admin/store/product/list. The manipulation of the argument cateId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-223738 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1608?
The severity of CVE-2023-1608 is critical with a severity value of 9.8.
Which software version is affected by CVE-2023-1608?
The Zhong Bang CRMEB Java version up to 1.3.4 is affected by CVE-2023-1608.
What is the vulnerability type for CVE-2023-1608?
The vulnerability type for CVE-2023-1608 is SQL injection.
How can the SQL injection vulnerability in CVE-2023-1608 be exploited?
The SQL injection vulnerability in CVE-2023-1608 can be exploited remotely by manipulating the argument cateId in the getAdminList function of the /api/admin/store/product/list file.
Are there any references available for CVE-2023-1608?
Yes, references for CVE-2023-1608 can be found at the following links: [Reference 1](https://vuldb.com/?id.223738), [Reference 2](https://vuldb.com/?ctiid.223738), [Reference 3](https://github.com/crmeb/crmeb_java/issues/11).