CVE-2024-24110: Crmeb Java

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spread/people.

Affected products

  • Crmeb Crmeb Java: before 1.3.4 (fixed in 1.3.4)

Published 2024-03-21. Last modified 2026-06-17.