Impact
The CRMEB Knowledge-Paid System crmeb_zzff_class version1.4.4 contains a backend verification function that incorrectly returns a value of the wrong type. This mismatch results in errors and the accidental leakage of sensitive information that should remain confidential, exposing a weakness in type validation and handling during verification.
Affected Systems
The affected product is the CRMEB Knowledge-Paid System crmeb_zzff_class version 1.4.4. No additional vendors or versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity. The EPSS score is < 1%, reflecting a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the flaw originates from a backend verification routine, a successful exploitation would likely require the ability to trigger that routine, which may demand authenticated or privileged access. Without an official exploit, the practical risk remains undetermined, but the potential for sensitive data leakage warrants prompt attention.
OpenCVE Enrichment