CVE-2014-7986: Medium severity espocrm vulnerability
Published Oct 31, 2014
·Updated
install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess parameter.
Affected Software
1 affected component
EspoCRM EspoCRM<=2.5.2
Remediation
Patch Available
Event History
Oct 31, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7986?
CVE-2014-7986 is classified as a medium severity vulnerability due to its potential for allowing remote attackers to reinstall the application.
2
How do I fix CVE-2014-7986?
To mitigate CVE-2014-7986, upgrade to EspoCRM version 2.6.0 or later, which resolves this vulnerability.
3
Who is affected by CVE-2014-7986?
CVE-2014-7986 affects EspoCRM installations prior to version 2.6.0.
4
What type of vulnerability is CVE-2014-7986?
CVE-2014-7986 is a remote installation vulnerability that allows attackers to reinstall the application.
5
What can attackers do with CVE-2014-7986?
With CVE-2014-7986, attackers can exploit the vulnerability to re-install the EspoCRM application by manipulating the installProcess parameter.