CVE-2014-7985

critical
Published 2014-10-31 · Modified 2026-05-06
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter to install/index.php.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://blog.espocrm.com/news/espocrm-2-6-0-released

Application impact

VendorProductVersionsFixed
espocrmespocrm{"endIncluding":"2.5.2"}

References

CWEs

CWE-22

Verify integrity in audit chain (admin only). AS-IS.