CVE-2022-38843
EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacker may execute these malicious files to run unintended code on the server to compromise the server.
- Affected products
- Espocrm
- Espocrm
- = 7.1.8
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.2% (64th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2022-09-16
CVE-2022-38843 at NVD
No indexed exploits for CVE-2022-38843 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-38843 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.