{"api_version":"1","generated_at":"2026-07-23T13:31:16+00:00","cve":"CVE-2023-41149","urls":{"html":"https://cve.report/CVE-2023-41149","api":"https://cve.report/api/cve/CVE-2023-41149.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-41149","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-41149"},"summary":{"title":"CVE-2023-41149","description":"F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploited, an attacker who can access the product may execute an arbitrary OS command on the server where the product is running.","state":"PUBLIC","assigner":"vultures@jpcert.or.jp","published_at":"2023-09-06 13:15:00","updated_at":"2023-09-08 21:21:00"},"problem_types":["CWE-78"],"metrics":[],"references":[{"url":"https://f-revocrm.jp/2023/08/9394/","name":"https://f-revocrm.jp/2023/08/9394/","refsource":"MISC","tags":[],"title":"F-RevoCRM version7.3系の脆弱性と対応について – CRM(顧客管理)ならオープンソースのF-RevoCRM","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://jvn.jp/en/jp/JVN78113802/","name":"http://jvn.jp/en/jp/JVN78113802/","refsource":"MISC","tags":[],"title":"JVN#78113802: Multiple vulnerabilities in F-RevoCRM","mime":"text/xml","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-41149","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-41149","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"41149","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"f-revocrm","cpe5":"f-revocrm","cpe6":"7.3.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"41149","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"f-revocrm","cpe5":"f-revocrm","cpe6":"7.3.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-41149","ASSIGNER":"vultures@jpcert.or.jp","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploited, an attacker who can access the product may execute an arbitrary OS command on the server where the product is running."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"OS command injection"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Thinkingreed Inc. ","product":{"product_data":[{"product_name":"F-RevoCRM ","version":{"version_data":[{"version_affected":"=","version_value":"version7.3.7 and version7.3.8 "}]}}]}}]}},"references":{"reference_data":[{"url":"https://f-revocrm.jp/2023/08/9394/","refsource":"MISC","name":"https://f-revocrm.jp/2023/08/9394/"},{"url":"http://jvn.jp/en/jp/JVN78113802/","refsource":"MISC","name":"http://jvn.jp/en/jp/JVN78113802/"}]}},"nvd":{"publishedDate":"2023-09-06 13:15:00","lastModifiedDate":"2023-09-08 21:21:00","problem_types":["CWE-78"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:f-revocrm:f-revocrm:7.3.8:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:f-revocrm:f-revocrm:7.3.7:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}