Impact
An authenticated attacker can submit a crafted POST request to the /adminapi/file/video_data_save endpoint of CRMEB v6.0.0, which causes the application to delete any file on the server without proper validation. This flaw enables the attacker to remove critical system or application files, potentially leading to data loss, service disruption, or compromise of system integrity.
Affected Systems
The vulnerability affects CRMEB software version 6.0.0. No other affected versions or vendors are listed in the data.
Risk and Exploitability
The flaw requires authentication but otherwise imposes no special prerequisites; once logged in, the attacker can trigger file deletion. No CVSS score is published, and the EPSS score is not available, making it unclear how often this flaw has been exploited. The vulnerability is not included in CISA’s KEV catalog, indicating that there have been no known widespread exploits at the time of reporting.
OpenCVE Enrichment