CVE-2023-5966

HIGH7.2EPSS 0.44%
Published: 3/6/2024Modified: 3/6/2024
Also known as:BIT-espocrm-2023-5966

Description

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary PHP code execution.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References (1)