← Back to browse · API

CVE-2020-25466

Severity
CRITICAL
CVSS
9.8
EPSS
0.0253
Risk score
40.09
CISA KEV
No
PoC
No
Published
2020-10-23
Modified
2026-07-09
First seen
2026-08-05
Aliases
EUVD-2020-18152, GHSA-VM4J-2MRW-2C59
Products
crmeb:crmeb, n/a:n/a n/a
Sources
nvd CVE-2020-25466
euvd EUVD-2020-18152

Description

A SSRF vulnerability exists in the downloadimage interface of CRMEB 3.0, which can remotely download arbitrary files on the server and remotely execute arbitrary code.

References