PT-2022-24594 · Espocrm · Espocrm
Published
2022-09-16
·
Updated
2024-03-06
·
CVE-2022-38844
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EsppoCRM version 7.1.8
Description
The issue allows remote authenticated users to run system commands via creating contacts with payloads capable of executing system commands. An admin user exporting contacts in a CSV file may end up executing the malicious system commands on their system.
Recommendations
For EspoCRM version 7.1.8, update to a version that includes a fix for this issue, as using the current version may allow malicious system commands to be executed. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Espocrm