GHSA-wcm6-243c-86f3HighCVSS 9.8
EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user...
🔗 CVE IDs covered (1)
📋 Description
EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized access to administrative user information and privileges.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2020-37094
- https://www.espocrm.com
- https://www.exploit-db.com/exploits/48376
- https://www.vulncheck.com/advisories/espocrm-privilege-escalation
- https://github.com/espocrm/espocrm/commit/b299220dd0c7acdaa1ed8be8ffd79c7985093c7a
- https://www.vulncheck.com/advisories/espocrm-two-factor-auth-bypass-via-auth-token-reuse-between-accounts-with-identical-passwords
- https://github.com/advisories/GHSA-wcm6-243c-86f3