Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7wx4-fjq2-2hjg

Опубликовано: 30 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary PHP code execution.

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary PHP code execution.

EPSS

Процентиль: 75%
0.00855
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.1
nvd
около 2 лет назад

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary PHP code execution.

EPSS

Процентиль: 75%
0.00855
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-434