在 EspoCRM 10.0.5 之前的版本中,PersonalAccount\Service 存在一个不安全的直接对象引用(IDOR)漏洞,允许具有 Email Account 作用域访问权限的用户获取其他用户的 IMAP 密码。攻击者如果知道受害者的 Email Account 记录 ID,就可以请求该记录,从而窃取存储的 IMAP 凭据并访问受害者的邮箱。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105831 | 4.3 MEDIUM | EspoCRM before 10.0.6 Unauthenticated Stored HTML Injection via Lead Capture Form |
| CVE-2026-105832 | 4.3 MEDIUM | EspoCRM before 10.0.6 Two-Factor Authentication Bypass on Unauthenticated Routes |
No comments yet