CVE-2023-30185: Crmeb

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.

Affected products

  • Crmeb Crmeb: from 4.4.0, up to and including 4.6.0

Published 2023-05-08. Last modified 2026-07-09.