PoC Index

CVE-2022-38843

HIGH 8.8EPSS 1.2%

EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacker may execute these malicious files to run unintended code on the server to compromise the server.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.19% chance of exploitation in the next 30 days, 66th percentile
Published
2022-09-16
Updated
2024-08-03

Proof-of-concept exploits (1)

References

Related