PT-2026-34553 · Espocrm · Espocrm

Published

2026-04-22

·

Updated

2026-04-22

·

CVE-2026-33733

CVSS v3.1

7.2

High

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled name and scope values and pass them into template path construction without normalization or traversal filtering. As a result, an authenticated admin can use ../ sequences to escape the intended template directory and read, create, overwrite, or delete arbitrary files that resolve to body.tpl or subject.tpl under the web application user's filesystem permissions. Version 9.3.4 fixes the issue.

Exploit

Fix

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2026-33733

Affected Products

Espocrm