CVE-2023-42335: FL3XX Crew
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code via the add attachment function in the New Expense component.
Affected products
Published 2023-09-20. Last modified 2026-06-17.