
# Authentifizierter RCE-Exploit für EspoCRM <= 9.3.3 (CVE-2026-33656) über Formula-ACL-Bypass, Path Traversal und .htaccess-Poisoning zur Erlangung von OS-Befehlsausführung.
Usage:
./poc.sh <base_url> <username> <password> [command]
Example:
./poc.sh http://192.168.5.16:8090 admin admin id