PT-2022-24593 · Espocrm · Espocrm

Published

2022-09-16

·

Updated

2024-03-06

·

CVE-2022-38843

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EspoCRM version 7.1.8
Description The issue allows attackers to upload malicious files with any extension to the server. These malicious files can be executed to run unintended code on the server, potentially compromising it.
Recommendations For EspoCRM version 7.1.8, update to a version that fixes the Unrestricted File Upload issue to prevent attackers from uploading malicious files. As a temporary workaround, consider restricting file uploads to only necessary extensions and validating all uploaded files to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BIT-ESPOCRM-2022-38843
CVE-2022-38843

Affected Products

Espocrm