PT-2026-34553 · Espocrm · Espocrm

Highyurikuzn

·

Published

2026-04-22

·

Updated

2026-04-23

·

CVE-2026-33733

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EspoCRM versions prior to 9.3.4
Description The admin template management endpoints accept attacker-controlled name and scope values and pass them into template path construction without normalization or traversal filtering. This allows an authenticated admin to use path traversal sequences to escape the intended template directory and read, create, overwrite, or delete arbitrary files that resolve to 'body.tpl' or 'subject.tpl' based on the web application user's filesystem permissions.
Recommendations Update to version 9.3.4.

Exploit

Fix

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33733

Affected Products

Espocrm