CVE-2023-5966: Unrestricted Upload of File with Dangerous Type in EspoCRM
Published Nov 30, 2023
·Updated
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary PHP code execution.
Affected Software
1 affected component
EspoCRM EspoCRM<=7.5.2
Remediation
Information
Users with administrator profile can load extensions and updates by design, as this is a functionality that most users use and request. It is possible to restrict exploitation of the vulnerability by enabling the "restrictedMode" option in the configuration menu.
Event History
Nov 30, 2023
CVE Published
via MITRE·01:26 PM
Data Sourced
via MITRE·01:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-5966?
CVE-2023-5966 is a vulnerability in EspoCRM that allows an authenticated attacker to upload a malicious zip file, leading to arbitrary PHP code execution.
2
How severe is CVE-2023-5966?
CVE-2023-5966 has a severity score of 9.1 (critical).
3
Which version of EspoCRM is affected by CVE-2023-5966?
EspoCRM version 7.2.5 up to and including 7.5.2 is affected by CVE-2023-5966.
4
How can an attacker exploit CVE-2023-5966?
An attacker with authenticated privileges can upload a specially crafted zip file via the extension deployment form in EspoCRM, which can lead to arbitrary PHP code execution.
5
How can I fix CVE-2023-5966?
To fix CVE-2023-5966, update EspoCRM to a version higher than 7.5.2.