PT-2026-84914 · Zhongbangkeji · Crmeb
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ZhongBangKeJi CRMEB versions prior to 6.0.0
Description
An OS command injection flaw exists in the Custom Scheduled Task Feature. The issue occurs when the
eval() function in the '/adminapi/system/crontab/save' endpoint processes the customCode variable. This allows a remote attacker to execute arbitrary operating system commands. Although the vendor describes this as debug-only behavior, the isSafePhpCode blacklist does not effectively prevent remote code execution (RCE), which is the ability to execute arbitrary code on a remote machine.Recommendations
Update to a version later than 6.0.0.
Restrict access to the '/adminapi/system/crontab/save' endpoint to minimize the risk of exploitation.
Exploit
Fix
RCE
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crmeb