Espocrm

Espocrm

43 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 28.05.2026 16:25:03
  • Zuletzt bearbeitet 28.05.2026 20:16:23

EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:id/prepare endpoint accepts an emailAddress parameter and resolves the owning entity (Contact, Lead, Account, or User) without per...

  • EPSS 0.29%
  • Veröffentlicht 28.05.2026 16:24:19
  • Zuletzt bearbeitet 28.05.2026 20:16:23

EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Access Control) in EspoCRM 9.3.3 allows low-privileged users to pin arbitrary notes without having the required edit permissions for...

  • EPSS 0.21%
  • Veröffentlicht 19.05.2026 18:14:36
  • Zuletzt bearbeitet 20.05.2026 14:16:42

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated users to upload SVG attachments through normal attachment-capable fields and later serve those SVG files as top-level inline document...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 22.04.2026 20:05:23
  • Zuletzt bearbeitet 27.04.2026 15:08:59

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled `name` and `scope` values and pass them into template path construction without normali...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 22.04.2026 20:01:24
  • Zuletzt bearbeitet 27.04.2026 17:04:54

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing updating attachment's sourceId thus allowing an authenticated admin to overwrite the `sourceId` field...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 13.04.2026 20:37:28
  • Zuletzt bearbeitet 22.04.2026 00:04:34

EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contains an Insecure Direct Object Reference (IDOR) vulnerability where the attacker-supplied fileId parame...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 13.04.2026 20:32:07
  • Zuletzt bearbeitet 22.04.2026 00:07:49

EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Attachment/fromImageUrl endpoint is vulnerable to Server-Side Request Forgery (SSRF) via a DNS rebinding (TOCTOU) condition. Host va...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 13.04.2026 19:41:47
  • Zuletzt bearbeitet 22.04.2026 00:10:21

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML injection vulnerability that allows any authenticated user with standard (non-administrative) privileges to inject arbitrary HTML into...

Exploit
  • EPSS 1.98%
  • Veröffentlicht 13.04.2026 19:20:04
  • Zuletzt bearbeitet 22.04.2026 00:12:27

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated Server-Side Request Forgery (SSRF) vulnerability that allows bypassing the internal-host validation logic by using alternative IPv4...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 03.02.2026 22:16:25
  • Zuletzt bearbeitet 03.03.2026 14:59:29

EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized a...