Poc from CVE-2023-5966 Advisory EspoCRM 274 and earlier is vulnerable to an arbitrary file upload that can lead to code execution in the add extension functionality The zip file on this repo upload a web shell to /webshellphp
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary PHP code execution.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
espocrm espocrm |