PT-2025-31880 · Espocrm · Espocrm
Saturnusdj
·
Published
2025-08-05
·
Updated
2025-08-05
·
CVE-2025-52892
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
EspoCRM versions 9.1.6 and below
Description
EspoCRM is a web application featuring a single-page application frontend and a PHP-based REST API backend. If a user accesses EspoCRM in a browser with double slashes (e.g.,
https://domain//#Admin) and the webserver does not remove the double slash, it can corrupt the Slim router's cache, rendering the instance unusable until the cache is rebuilt.Recommendations
Upgrade to version 9.1.7 or later.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Espocrm