← Back to browse · API

CVE-2022-46610

Severity
HIGH
CVSS
8.8
EPSS
0.18087
Risk score
41.53
CISA KEV
No
PoC
No
Published
2023-01-10
Modified
2025-04-09
First seen
2026-08-07
Aliases
EUVD-2022-49414, GHSA-2WX5-X3V9-H4FR
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-49414

Description

72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

References