EspoCRM versions prior to 9.3.4 contain vulnerabilities that allow authenticated admins to overwrite the `sourceId` field on attachments and inject malicious templates through unnormalized input parameters.
Claims
EspoCRM versions prior to 9.3.4 contain vulnerabilities that allow authenticated admins to overwrite the `sourceId` field on attachments and inject malicious templates through unnormalized input parameters.
Parent: CybersecurityEntity: EspoCRMImpact: negativeDate: Apr 23, 2026Target: EspoCRM's security practices and vulnerability management
Source posts
๐จ EUVD-2026-25081
๐ Score: 9.1/10 (CVSS v3.1)
๐ฆ Product: espocrm
๐ข Vendor: espocrm
๐
Updated: 2026-04-22
๐ EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing updating attachment's sourceId thus allowing an authenticated admin to overwrite the `sourceId` field on `Att...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25081
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25082
๐ Score: 7.2/10 (CVSS v3.1)
๐ฆ Product: espocrm
๐ข Vendor: espocrm
๐
Updated: 2026-04-22
๐ EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled `name` and `scope` values and pass them into template path construction without normalization o...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25082
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability