CVE-2024-24818: Espocrm
Medium severity, CVSS 5.9. EPSS: 0.6% chance of exploitation in the next 30 days.
EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim to malicious page that could lead to credential stealing or another attack. This vulnerability is fixed in 8.1.2.
Affected products
- Espocrm Espocrm: before 8.1.2 (fixed in 8.1.2)
Published 2024-03-21. Last modified 2026-06-17.