• caglararli@hotmail.com
  • 05386281520

CVE-2023-46736 | EspoCRM up to 8.0.4 Upload Image From URL API /Attachment/fromImageUrl server-side request forgery (GHSA-g955-rwxx-jvf6)

CVE-2023-46736 | EspoCRM up to 8.0.4 Upload Image From URL API /Attachment/fromImageUrl server-side request forgery (GHSA-g955-rwxx-jvf6)

A vulnerability, which was classified as problematic, was found in EspoCRM up to 8.0.4. This affects an unknown part of the file /Attachment/fromImageUrl of the component Upload Image From URL API. The manipulation leads to server-side request forgery. This vulnerability is uniquely identified as CVE-2023-46736. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.