Skip to content
COOEY

EXPOSURES › CVE-2023-30185

CVE-2023-30185

CRITICAL
DETAIL
SourceNVD · cve Published2023-05-08 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-30185 ↗
⚡ RCE SHAME 50/100 rce

CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.