Remote Code Execution via installProcess Parameter in EspoCRM

Remote Code Execution via installProcess Parameter in EspoCRM

CVE-2014-7986 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:N/A:P

install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess parameter.

Learn more about our Crm Penetration Testing.