Description
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could lead to arbitrary PHP code execution.
Remediation
References
Related Vulnerabilities
WordPress Plugin CMP-Coming Soon & Maintenance by NiteoThemes Security Bypass (3.8.1)
PHP Other Vulnerability (CVE-2007-1885)
WordPress Plugin WP Symposium 'get_profile_avatar.php' SQL Injection (0.64)
WordPress Plugin Portfolio by BestWebSoft Multiple Cross-Site Scripting Vulnerabilities (2.27)
ASP.NET MVC Improper Input Validation Vulnerability (CVE-2017-0247)