CVE-2024-24818

MEDIUM

EspoCRM < 8.1.2 - Open Redirect via Password Change Page

Title source: llm
STIX 2.1

Description

EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim to malicious page that could lead to credential stealing or another attack. This vulnerability is fixed in 8.1.2.

Scores

CVSS v3 5.9
EPSS 0.0062
EPSS Percentile 44.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-610 CWE-601
Status published
Products (1)
espocrm/espocrm < 8.1.2
Published Mar 21, 2024
Tracked Since Feb 18, 2026