cve/2023/CVE-2023-5966.md
2024-05-25 21:48:12 +02:00

793 B

CVE-2023-5966

Description

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary PHP code execution.

POC

Reference

No PoCs from references.

Github