PT-2025-20690 · Espocrm · Espocrm

Xorriath

·

Published

2025-05-12

·

Updated

2025-05-12

·

CVE-2025-32390

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions EspoCRM versions prior to 9.0.8
Description The issue allows for HTML Injection in Knowledge Base (KB) articles, leading to complete page defacement that can imitate the login page. Authenticated users with the read knowledge article privilege can be impacted, and if they submit their credentials, they get captured in plain text. This is due to overly permissive HTML editing being allowed on the KB articles. In an enterprise setting, the vulnerability could be exploited to harvest credentials for other applications by making the malicious KB article resemble the login pages of those applications.
Recommendations For versions prior to 9.0.8, update to version 9.0.8 to resolve the issue. As a temporary workaround, consider restricting access to editing KB articles to prevent malicious modifications. Additionally, advise users to be cautious when submitting credentials on pages that resemble the login page but are accessed through KB articles.

Exploit

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2025-32390
GHSA-QRWP-V8V3-HQP2

Affected Products

Espocrm