SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/phtcloud-dev/CVE-2024-36837 |
|
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T03:43:49.147Z
Reserved: 2024-05-30T00:00:00
Link: CVE-2024-36837
Updated: 2024-08-02T03:43:49.147Z
Status : Modified
Published: 2024-06-05T15:15:11.803
Modified: 2024-11-21T09:22:41.213
Link: CVE-2024-36837
No data.
OpenCVE Enrichment
No data.
Weaknesses