CVE-2024-36837: Crmeb

High severity, CVSS 7.5. EPSS: 8.3% chance of exploitation in the next 30 days.

SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in the ProductController.php file.

Affected products

  • Crmeb Crmeb: version 5.2.2 only

Published 2024-06-05. Last modified 2026-06-17.