CVE-2022-38843: Malicious File Upload
EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacker may execute these malicious files to run unintended code on the server to compromise the server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38843?
CVE-2022-38843 is a vulnerability in EspoCRM version 7.1.8 that allows attackers to upload malicious files with any extension to the server.
What is the severity of CVE-2022-38843?
CVE-2022-38843 has a severity rating of 8.8, which is considered high.
How does CVE-2022-38843 affect EspoCRM?
CVE-2022-38843 affects EspoCRM version 7.1.8 by allowing attackers to compromise the server through the execution of malicious files.
Is there a fix available for CVE-2022-38843?
At the moment, there is no official fix available for CVE-2022-38843. It is recommended to update to a newer version of the software when a patch is released.
Where can I find more information about CVE-2022-38843?
You can find more information about CVE-2022-38843 on the following link: [EspoCRM Unrestricted File Upload Vulnerability](https://medium.com/cybersecurity-valuelabs/espocrm-7-1-8-is-vulnerable-to-unrestricted-file-upload-7860b15d12bc)