CVE-2024-28714: Crmeb Java

High severity, CVSS 8.1. EPSS: 0.8% chance of exploitation in the next 30 days.

SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.

Affected products

  • Crmeb Crmeb Java: before 1.3.4 (fixed in 1.3.4)

Published 2024-03-28. Last modified 2026-07-09.