PT-2026-93257 · Espocrm · Espocrm
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
EspoCRM versions prior to 10.0.9
Description
The software uses the PHP
rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs. Because rand() is not a cryptographically secure generator, remote unauthenticated attackers can guess these approximately 31-bit tokens. This allows attackers to confirm opt-ins, accept or decline event invitations on behalf of other contacts, and access event details.Recommendations
Update EspoCRM to version 10.0.9 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Espocrm