โ† All reports

EspoCRM versions prior to 9.3.4 contain vulnerabilities that allow authenticated admins to overwrite the `sourceId` field on attachments and inject malicious templates through unnormalized input parameters.

CybersecurityTechnologyConflictApr 23, 2026score 0.172 posts ยท 0 replies across 1 instances
The thread discusses two vulnerabilities in EspoCRM, an open-source customer relationship management application, highlighting security risks in its formula scripting engine and admin template management endpoints. These vulnerabilities could allow authenticated admins to overwrite fields and inject malicious templates, respectively, posing a threat to data integrity and system security.

Claims

EspoCRM versions prior to 9.3.4 contain vulnerabilities that allow authenticated admins to overwrite the `sourceId` field on attachments and inject malicious templates through unnormalized input parameters.
Parent: CybersecurityEntity: EspoCRMImpact: negativeDate: Apr 23, 2026Target: EspoCRM's security practices and vulnerability management

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-25081 ๐Ÿ“Š Score: 9.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: espocrm ๐Ÿข Vendor: espocrm ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing updating attachment's sourceId thus allowing an authenticated admin to overwrite the `sourceId` field on `Att... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25081 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-25082 ๐Ÿ“Š Score: 7.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: espocrm ๐Ÿข Vendor: espocrm ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled `name` and `scope` values and pass them into template path construction without normalization o... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25082 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability