An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary PHP code execution.
2023-11-30T14:15:13.450
2024-11-21T08:42:52.887
Modified
CVSSv3.1: 9.1 (CRITICAL)