First published: Fri Sep 16 2022(Updated: )
EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacker may execute these malicious files to run unintended code on the server to compromise the server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
EspoCRM | =7.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38843 is a vulnerability in EspoCRM version 7.1.8 that allows attackers to upload malicious files with any extension to the server.
CVE-2022-38843 has a severity rating of 8.8, which is considered high.
CVE-2022-38843 affects EspoCRM version 7.1.8 by allowing attackers to compromise the server through the execution of malicious files.
At the moment, there is no official fix available for CVE-2022-38843. It is recommended to update to a newer version of the software when a patch is released.
You can find more information about CVE-2022-38843 on the following link: [EspoCRM Unrestricted File Upload Vulnerability](https://medium.com/cybersecurity-valuelabs/espocrm-7-1-8-is-vulnerable-to-unrestricted-file-upload-7860b15d12bc)