7.2
CVSSv3

CVE-2023-5965

Published: 30/11/2023 Updated: 06/12/2023
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could lead to arbitrary PHP code execution.

Vulnerable Product Search on Vulmon Subscribe to Product

espocrm espocrm

Github Repositories

POC cve-2023-5965 Advisory EspoCRM 274 and earlier is vulnerable to an arbitrary file upload that can lead to code execution in the add upgrade functionality The zip file on this repo upload a web shell to /webshellphp