CVE-2020-25466: Crmeb
Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
Affected products
- Crmeb Crmeb: version 3.0 only
Published 2020-10-23. Last modified 2026-07-09.