Review reviewCritical
CVE-2020-25466
crmeb
A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.
- CVSS
- 9.8
- EPSS
- 2.53% 83.4% percentile
- CISA KEV
- Not listed
- Published
- 2020.10.24