Executive brief
CRMEB Knowledge-Paid System is a knowledge commerce platform combining live streaming, video on demand, and affiliate distribution. A backend verification function returns an incorrect data type, causing application errors and exposing sensitive information to unauthorized parties.
Technical details
A type confusion vulnerability exists in the crmeb_zzff_class backend verification function where incorrect return type handling allows information disclosure. The flaw enables exposure of sensitive data through error responses or improper type casting. The vulnerability affects version 1.4.4 and appears exploitable through backend access.
Affected products
- CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4
Timeline
- 2026-09-21: disclosed