EspoCRM 10.0.6 之前的版本存在一个身份验证绕过漏洞。该漏洞允许攻击者在无需身份验证的路由上,跳过第二因素(2FA)验证,而系统仅停留在第二因素验证阶段。已知具备第二因素验证功能用户的用户名和密码的攻击者,可以绕过第二因素验证,从而读取未公开配置的参数信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105833 | 7.7 HIGH | EspoCRM before 10.0.5 IDOR via PersonalAccount Service Exposes IMAP Passwords |
| CVE-2026-105831 | 4.3 MEDIUM | EspoCRM before 10.0.6 Unauthenticated Stored HTML Injection via Lead Capture Form |
No comments yet