CVE-2023-5966
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary PHP code execution.
- Affected products
- Espocrm
- Espocrm
- ≤ 7.5.2
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 1.0% (62th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2023-11-30
Fix
Users with administrator profile can load extensions and updates by design, as this is a functionality that most users use and request. It is possible to restrict exploitation of the vulnerability by enabling the "restrictedMode" option in the configuration menu.
CVE-2023-5966 at NVD
2 known exploits for CVE-2023-5966
Proof-of-concept code and exploit modules indexed by Sploitus