CVE-2022-38843

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
16/09/2022
Last modified:
17/09/2022

Description

EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacker may execute these malicious files to run unintended code on the server to compromise the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:espocrm:espocrm:7.1.8:*:*:*:*:*:*:*