Vulnerability Details CVE-2023-30185
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 62.4%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-30185
-
cpe:2.3:a:crmeb:crmeb:4.4.0
-
cpe:2.3:a:crmeb:crmeb:4.4.2
-
cpe:2.3:a:crmeb:crmeb:4.4.4
-
cpe:2.3:a:crmeb:crmeb:4.6.0