CVE-2023-5965
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could lead to arbitrary PHP code execution.
- Affected products
- Espocrm
- Espocrm
- ≤ 7.5.2
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 1.0% (62th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2023-11-30
Fix
Users with administrator profile can load extensions and updates by design, as this is a functionality that most users use and request. It is possible to restrict exploitation of the vulnerability by enabling the "restrictedMode" option in the configuration menu.
CVE-2023-5965 at NVD
1 known exploit for CVE-2023-5965
Proof-of-concept code and exploit modules indexed by Sploitus