# Poc from CVE-2023-5966
[Advisory](https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-espocrm)
EspoCRM 2.7.4 and earlier is vulnerable to an arbitrary file upload that can lead to code execution in the add extension functionality.
The zip file on this repo upload a web shell to /webshell.php
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view