PT-2024-20584 · Espocrm · Espocrm
Kerkroups
·
Published
2024-02-29
·
Updated
2025-06-27
·
CVE-2024-24818
CVSS v3.1
5.9
Medium
| Vector | AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
EspoCRM versions prior to 8.1.2
Description
The issue allows an attacker to inject arbitrary IP or domain in the "Password Change" page, potentially redirecting the victim to a malicious page. This could lead to credential stealing or other attacks.
Recommendations
For versions prior to 8.1.2, update to version 8.1.2 to resolve the issue.
As a temporary workaround, consider restricting access to the "Password Change" page until the update is applied.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Espocrm