{"api_version":"1","generated_at":"2026-06-04T17:42:41+00:00","cve":"CVE-2023-1609","urls":{"html":"https://cve.report/CVE-2023-1609","api":"https://cve.report/api/cve/CVE-2023-1609.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-1609","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-1609"},"summary":{"title":"CVE-2023-1609","description":"A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been rated as problematic. This issue affects the function save of the file /api/admin/store/product/save. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223739.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2023-03-23 20:15:00","updated_at":"2023-11-07 04:04:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://vuldb.com/?id.223739","name":"https://vuldb.com/?id.223739","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://vuldb.com/?ctiid.223739","name":"https://vuldb.com/?ctiid.223739","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://github.com/crmeb/crmeb_java/issues/12","name":"https://github.com/crmeb/crmeb_java/issues/12","refsource":"MISC","tags":[],"title":"There is a stored XSS vulnerability in the /api/admin/store/product/save interface of the crmeb_java system · Issue #12 · crmeb/crmeb_java · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-1609","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1609","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"1609","vulnerable":"1","versionEndIncluding":"1.3.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"crmeb","cpe5":"crmeb_java","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-1609","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been rated as problematic. This issue affects the function save of the file /api/admin/store/product/save. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223739."},{"lang":"deu","value":"Eine Schwachstelle wurde in Zhong Bang CRMEB Java bis 1.3.4 ausgemacht. Sie wurde als problematisch eingestuft. Hierbei geht es um die Funktion save der Datei /api/admin/store/product/save. Durch Beeinflussen mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-79 Cross Site Scripting","cweId":"CWE-79"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Zhong Bang","product":{"product_data":[{"product_name":"CRMEB Java","version":{"version_data":[{"version_affected":"=","version_value":"1.3.0"},{"version_affected":"=","version_value":"1.3.1"},{"version_affected":"=","version_value":"1.3.2"},{"version_affected":"=","version_value":"1.3.3"},{"version_affected":"=","version_value":"1.3.4"}]}}]}}]}},"references":{"reference_data":[{"url":"https://vuldb.com/?id.223739","refsource":"MISC","name":"https://vuldb.com/?id.223739"},{"url":"https://vuldb.com/?ctiid.223739","refsource":"MISC","name":"https://vuldb.com/?ctiid.223739"},{"url":"https://github.com/crmeb/crmeb_java/issues/12","refsource":"MISC","name":"https://github.com/crmeb/crmeb_java/issues/12"}]},"credits":[{"lang":"en","value":"Mechoy (VulDB User)"}],"impact":{"cvss":[{"version":"3.1","baseScore":3.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"},{"version":"3.0","baseScore":3.5,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"},{"version":"2.0","baseScore":4,"vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N"}]}},"nvd":{"publishedDate":"2023-03-23 20:15:00","lastModifiedDate":"2023-11-07 04:04:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:crmeb:crmeb_java:*:*:*:*:*:*:*:*","versionEndIncluding":"1.3.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}