CVE-2022-38843

EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacker may execute these malicious files to run unintended code on the server to compromise the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:espocrm:espocrm:7.1.8:*:*:*:*:*:*:*

History

21 Nov 2024, 07:17

Type Values Removed Values Added
References () https://medium.com/cybersecurity-valuelabs/espocrm-7-1-8-is-vulnerable-to-unrestricted-file-upload-7860b15d12bc - Exploit, Third Party Advisory () https://medium.com/cybersecurity-valuelabs/espocrm-7-1-8-is-vulnerable-to-unrestricted-file-upload-7860b15d12bc - Exploit, Third Party Advisory

Information

Published : 2022-09-16 14:15

Updated : 2024-11-21 07:17


NVD link : CVE-2022-38843

Mitre link : CVE-2022-38843

CVE.ORG link : CVE-2022-38843


JSON object : View

Products Affected

espocrm

  • espocrm
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type