PT-2023-30176 · Espocrm · Espocrm

Asesidaa

·

Published

2023-12-05

·

Updated

2024-03-06

·

CVE-2023-46736

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions EspoCRM versions prior to 8.0.5
Description The issue is related to a Server-Side Request Forgery (SSRF) vulnerability via the upload image from URL API. Users with access to the /Attachment/fromImageUrl endpoint can specify a URL to point to an internal host. Although there is a check for content type, it can be bypassed by redirects in some cases. This SSRF can be leveraged to disclose internal information, target internal hosts, and bypass firewalls.
Recommendations For versions prior to 8.0.5, upgrade to release version 8.0.5 or later to address the vulnerability. As a temporary workaround, consider restricting access to the /Attachment/fromImageUrl endpoint until the issue is resolved. Additionally, be cautious when using the upload image from URL API to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ESPOCRM-2023-46736
CVE-2023-46736
GHSA-G955-RWXX-JVF6

Affected Products

Espocrm