Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-5965

Опубликовано: 30 нояб. 2023
Источник: nvd
CVSS3: 9.1
CVSS3: 7.2
EPSS Низкий

Описание

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could lead to arbitrary PHP code execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:*
Версия до 7.5.2 (включая)

EPSS

Процентиль: 78%
0.01168
Низкий

9.1 Critical

CVSS3

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.1
github
около 2 лет назад

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could lead to arbitrary PHP code execution.

EPSS

Процентиль: 78%
0.01168
Низкий

9.1 Critical

CVSS3

7.2 High

CVSS3

Дефекты

CWE-434