Aller au contenu

Fiche vulnérabilité

CVE-2026-1202 : faille critique crmeb crmeb (CVSS 9.8)

Description

A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/LoginController.php. Performing a manipulation of the argument openId results in improper authentication. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
20 janv. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • crmeb crmeb

Références

Rechercher une autre vulnérabilité dans la base CVE