CVE-2023-3233: Zhong Bang CRMEB PublicController.php get_image_base64 server-side request forgery
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been classified as critical. Affected is the function getimagebase64 of the file api/controller/v1/PublicController.php. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231504. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3233?
CVE-2023-3233 has been classified as critical due to its potential for server-side request forgery.
How do I fix CVE-2023-3233?
To fix CVE-2023-3233, upgrade the Zhong Bang CRMEB software to version 4.6.1 or later.
What type of vulnerability is CVE-2023-3233?
CVE-2023-3233 is a server-side request forgery (SSRF) vulnerability found in the get_image_base64 function.
Which versions of CRMEB are affected by CVE-2023-3233?
CRMEB versions up to and including 4.6.0 are affected by CVE-2023-3233.
What is the impact of CVE-2023-3233?
The impact of CVE-2023-3233 includes the ability for an attacker to perform unauthorized server-side requests.