CVE-2025-11288 | CRMEB up to 5.6 GET Parameter product cate_id sql injection

SecurityVulns

A vulnerability was found in CRMEB up to 5.6. It has been classified as critical. This issue affects some unknown processing of the file /adminapi/product/product of the component GET Parameter Handler. Performing manipulation of the argument cate_id results in sql injection.

This vulnerability is known as CVE-2025-11288. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More