Vulnerability Details CVE-2022-46610
72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.032
EPSS Ranking 86.3%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2022-46610
-
cpe:2.3:a:72crm:wukong_crm:9.0