CVE-2023-5965
30.11.2023, 14:15
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could lead to arbitrary PHP code execution.Enginsight
Vendor | Product | Version |
---|---|---|
espocrm | espocrm | 𝑥 ≤ 7.5.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration