Espocrm

Espocrm

34 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.31%
  • Veröffentlicht 03.02.2026 22:16:25
  • Zuletzt bearbeitet 03.03.2026 14:59:29

EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized a...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 14.10.2025 14:38:20
  • Zuletzt bearbeitet 20.10.2025 18:12:29

EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows arbitrary user creation, including administrative accounts, through a combination of stored SVG injection and lack of CSRF protec...

  • EPSS 0.04%
  • Veröffentlicht 05.08.2025 00:17:16
  • Zuletzt bearbeitet 11.09.2025 17:14:04

EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP. In versions 9.1.6 and below, if a user loads Espo in the browser with double slashes (e.g https://domain//#Admin) and the webser...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 21.07.2025 17:48:11
  • Zuletzt bearbeitet 05.08.2025 17:53:32

EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulnerable to blind LDAP Injection when LDAP authentication is enabled. A remote, unauthenticated attacker can manipulate LDAP queries b...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 12.05.2025 10:30:52
  • Zuletzt bearbeitet 17.06.2025 19:41:34

EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Knowledge Base (KB) articles leads to complete page defacement imitating the login page. Authenticated users with the read knowledge a...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 16.04.2025 21:45:21
  • Zuletzt bearbeitet 18.06.2025 13:08:03

EspoCRM is an Open Source Customer Relationship Management software. Prior to version 9.0.7, users can be sorted by their password hash. This flaw allows an attacker to make assumptions about the hash values of other users stored in the password colu...

  • EPSS 0.22%
  • Veröffentlicht 15.04.2025 23:23:58
  • Zuletzt bearbeitet 27.06.2025 15:51:15

EspoCRM is an Open Source Customer Relationship Management software. Prior to 9.0.5, Iframe dashlet allows user to display iframes with arbitrary URLs. As the sandbox attribute is not included in the iframe, the remote page can open popups outside of...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 21.03.2024 02:52:12
  • Zuletzt bearbeitet 27.06.2025 14:35:32

EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim to malicious page that could lead to credential stealing or another attack. This vulnera...

  • EPSS 0.07%
  • Veröffentlicht 05.12.2023 21:15:07
  • Zuletzt bearbeitet 21.11.2024 08:29:11

EspoCRM is an Open Source CRM (Customer Relationship Management) software. In affected versions there is Server-Side Request Forgery (SSRF) vulnerability via the upload image from url api. Users who have access to `the /Attachment/fromImageUrl` endpo...

  • EPSS 0.86%
  • Veröffentlicht 30.11.2023 14:15:13
  • Zuletzt bearbeitet 21.11.2024 08:42:52

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary PHP code execution.