← Back

CVE-2024-24818

nvd nist
Published: Mar 21, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L
Exploitability: 1.2 / Impact: 4.7
Source: security-advisories@github.com (Secondary)

Description

EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim to malicious page that could lead to credential stealing or another attack. This vulnerability is fixed in 8.1.2.

Affected (1)

Products: Espocrm: Espocrm
1 product
Espocrm
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 8.1.2

References (4)

Source: security-advisories@github.com
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory

Timeline

No history available yet.