Impact
A flaw in ZhongBangKeJi's CRMEB platform allows a remote attacker to inject arbitrary OS commands through the customCode field that is processed by an eval call in the /adminapi/system/crontab/save endpoint. The vulnerability arises from unsanitized input leading to command execution (CWE-77) and unsafe eval usage (CWE-78). If exploited, an attacker can run arbitrary commands on the host, compromising confidentiality, integrity, and availability of the system.
Affected Systems
ZhongBangKeJi:CRMEB versions up to and including 6.0.0 are affected. No later versions have been verified as free of the flaw.
Risk and Exploitability
The CVSS v3.1 score of 5.1 indicates moderate severity, but the presence of a publicly available exploit and the fact that the flaw can be triggered remotely raise concern. The EPSS score of 2% indicates a low but non-negligible probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. The attack vector appears to be remote, likely via authenticated requests to the admin API endpoint, though the exact authentication prerequisite is not specified. Consequently, the risk remains significant for exposed installations that have not applied the fix.
OpenCVE Enrichment