CVE-2024-36837: SQL Injection
Published Jun 5, 2024
·Updated
SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.
Affected Software
1 affected component
crmeb crmeb=5.2.2
Event History
Jun 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-36837?
CVE-2024-36837 has a high severity rating due to its potential to expose sensitive information through SQL injection.
2
How do I fix CVE-2024-36837?
To fix CVE-2024-36837, upgrade CRMEB to a patched version that addresses the SQL injection vulnerability.
3
What systems are affected by CVE-2024-36837?
CVE-2024-36837 affects CRMEB version 5.2.2, which contains the vulnerable getProductList function.
4
Can CVE-2024-36837 be exploited remotely?
Yes, CVE-2024-36837 can be exploited remotely by an attacker to gain unauthorized access to sensitive information.
5
What kind of data can be accessed through CVE-2024-36837?
Through CVE-2024-36837, an attacker can obtain sensitive information from the database via SQL injection.