Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacker may execute these malicious files to run unintended code on the server to compromise the server.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
EspoCRM 代码问题漏洞
Vulnerability Description
EspoCRM是一套开源的基于Web的客户关系管理系统(CRM)。该系统提供销售自动化、社区和客户支持等功能。 EspoCRM 7.1.8版本存在代码问题漏洞,该漏洞源于容易受到无限制文件上传的攻击,允许攻击者将带有任何扩展名的恶意文件上传到服务器,攻击者可能会执行这些恶意文件,在服务器上运行非预期代码,从而破坏服务器。
CVSS Information
N/A
Vulnerability Type
N/A