# Poc from CVE-2023-5966
[Advisory](https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-espocrm)
EspoCRM 2.7.4 and earlier is vulnerable to an arbitrary file upload that can lead to code execution in the add extension functionality.
The zip file on this repo upload a web shell to /webshell.php
登录后查看神龙缓存的 POC 文件快照
登录查看