PT-2026-5844 · Espocrm · Espocrm

Publicado

2026-02-03

·

Atualizado

2026-03-03

·

CVE-2020-37094

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EspoCRM version 5.8.5
Description The software contains an authentication issue that allows unauthorized access to user accounts. Attackers can manipulate authorization headers, specifically decoding and modifying Basic Authorization and Espo-Authorization tokens, to gain access to administrative user information and privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2020-37094

Produtos afetados

Espocrm