EspoCRM 10.0.6 之前的版本存在一个存储型 HTML 注入漏洞,攻击者无需身份验证即可通过构造恶意数据提交到“潜在客户捕获”(Lead Capture)公共表单,从而注入 HTML 内容。这些请求体数据会被存储在 字段中,并在管理员查看日志记录时被未经转义地渲染出来。尽管内容安全策略(CSP)限制了 JavaScript 的执行,但 HTML 注入仍然可能发生。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105833 | 7.7 HIGH | EspoCRM before 10.0.5 IDOR via PersonalAccount Service Exposes IMAP Passwords |
| CVE-2026-105832 | 4.3 MEDIUM | EspoCRM before 10.0.6 Two-Factor Authentication Bypass on Unauthenticated Routes |
No comments yet