CyberRota Analysis
AI-GeneratedA vulnerability exists in the Custom Scheduled Task Feature of ZhongBangKeJi CRMEB versions up to 6.0.0, allowing remote attackers to exploit the eval function in the /adminapi/system/crontab/save file through manipulated customCode arguments, leading to OS command injection. This weakness poses a medium severity risk, as it can be exploited publicly, potentially compromising system integrity. Organizations using affected versions should prioritize remediation to mitigate the risk of unauthorized command execution.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A weakness has been identified in ZhongBangKeJi CRMEB up to 6.0.0. Affected by this vulnerability is the function eval of the file /adminapi/system/crontab/save of the component Custom Scheduled Task Feature. This manipulation of the argument customCode causes os command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Vendor documents this as deliberate debug-only behavior. But isSafePhpCode blacklist offers no real RCE containment.