First published: Fri Oct 31 2014(Updated: )
install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
EspoCRM | <=2.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7986 is classified as a medium severity vulnerability due to its potential for allowing remote attackers to reinstall the application.
To mitigate CVE-2014-7986, upgrade to EspoCRM version 2.6.0 or later, which resolves this vulnerability.
CVE-2014-7986 affects EspoCRM installations prior to version 2.6.0.
CVE-2014-7986 is a remote installation vulnerability that allows attackers to reinstall the application.
With CVE-2014-7986, attackers can exploit the vulnerability to re-install the EspoCRM application by manipulating the installProcess parameter.