#crmeb

RedPacket SecurityRedPacketSecurity
2026-01-20
Offensive Sequenceoffseq@infosec.exchange
2025-10-05

CVE-2025-11288 (MEDIUM): SQL injection in CRMEB 5.0–5.6 via cate_id at /adminapi/product/product. Exploit is public, vendor silent, no patch. Audit & mitigate now—input validation & access controls recommended. radar.offseq.com/threat/cve-20 #OffSeq #SQLi #CRMEB

Medium threat: CVE-2025-11288: SQL Injection in CRMEB

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst