CVE-2025-11288 | CRMEB up to 5.6 GET Parameter product cate_id sql injection
A vulnerability was found in CRMEB up to 5.6. It has been classified as critical. This issue affects some unknown processing of the file /adminapi/product/product of the component GET Parameter Handler. Performing manipulation of the argument cate_id results in sql injection.
This vulnerability is known as CVE-2025-11288. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More