CVE-2020-15958: 1crm

High severity, CVSS 8.6. EPSS: 3.2% chance of exploitation in the next 30 days.

An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthenticated request with a predictable URL.

Affected products

  • 1crm 1crm: up to and including 8.6.7

Published 2020-09-18. Last modified 2026-06-17.