NA

CVE-2023-5966

Published: 30/11/2023 Updated: 06/12/2023
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary PHP code execution.

Vulnerable Product Search on Vulmon Subscribe to Product

espocrm espocrm

Github Repositories

Poc from CVE-2023-5966 Advisory EspoCRM 274 and earlier is vulnerable to an arbitrary file upload that can lead to code execution in the add extension functionality The zip file on this repo upload a web shell to /webshellphp