Impact
An authenticated Server‑Side Request Forgery flaw exists in the /adminapi/file/online_upload component of CRMEB, allowing an attacker who can successfully authenticate to the administrative interface to issue a crafted POST request that causes the server to perform arbitrary HTTP requests to any internal network resource. This flaw is a CWE-918 vulnerability, indicating a Server‑Side Request Forgery. The vulnerability does not provide remote code execution, but the ability to access internal endpoints can facilitate data leaks, network reconnaissance, and may be used as a stepping stone for further attacks.
Affected Systems
This issue affects CRMEB version 6.0.0. No additional vendor or product versions are listed in the official advisory. The vulnerability is tied specifically to the online_upload API endpoint exposed to authenticated users.
Risk and Exploitability
The vulnerability receives a CVSS score of 8.1, indicating high severity. An EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector requires prior authentication to the admin API; an attacker sends a POST request to the /adminapi/file/online_upload endpoint and supplies a URL that points to an internal IP address, causing the server to retrieve that resource. The exploit does not demand arbitrary system access beyond the normal authenticated session and relies on the server’s outbound network connectivity.
OpenCVE Enrichment