Medium severity6.5NVD Advisory· Published Mar 21, 2024· Updated Jun 17, 2026
CVE-2024-24110
CVE-2024-24110
Description
SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spread/people.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<1.3.4+ 1 more
- (no CPE)range: <1.3.4
- cpe:2.3:a:crmeb:crmeb_java:*:*:*:*:*:*:*:*range: <1.3.4
- crmeb_java/crmeb_javadescription
Patches
Vulnerability mechanics
References
1- github.com/crmeb/crmeb_java/issues/13nvdExploitIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.