CVE-2023-30185: Malicious File Upload
Published May 8, 2023
·Updated
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.
Affected Software
1 affected component
crmeb crmeb>=4.4.0<=4.6.0
Event History
May 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
01:15 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-30185?
CVE-2023-30185 is an arbitrary file upload vulnerability found in CRMEB v4.4 to v4.6 via the component \attachment\SystemAttachmentServices.php.
2
How severe is CVE-2023-30185?
CVE-2023-30185 has a severity level of critical with a CVSS score of 9.8.
3
How does CVE-2023-30185 affect CRMEB?
CVE-2023-30185 affects CRMEB versions 4.4 to 4.6.
4
How can I fix CVE-2023-30185?
To fix CVE-2023-30185, it is recommended to update CRMEB to a version beyond 4.6.0.
5
Where can I find more information about CVE-2023-30185?
More information about CVE-2023-30185 can be found on the CRMEB website, the CVE-2023-30185 GitHub repository, and the CRMEB documentation.