EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulnerable to blind LDAP Injection when LDAP authentication is enabled. A remote, unauthenticated attacker can manipulate LDAP queries by injecting crafted input containing wildcard characters (e.g., *). This may allow the attacker to bypass authentication controls, enumerate valid usernames, or retrieve sensitive directory information depending on the LDAP server configuration. This was fixed in version 9.1.7.
Metrics
Affected Vendors & Products
References
History
Tue, 22 Jul 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Espocrm
Espocrm espocrm |
|
Vendors & Products |
Espocrm
Espocrm espocrm |
Mon, 21 Jul 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 21 Jul 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulnerable to blind LDAP Injection when LDAP authentication is enabled. A remote, unauthenticated attacker can manipulate LDAP queries by injecting crafted input containing wildcard characters (e.g., *). This may allow the attacker to bypass authentication controls, enumerate valid usernames, or retrieve sensitive directory information depending on the LDAP server configuration. This was fixed in version 9.1.7. | |
Title | EspoCRM vulnerable to LDAP Injection through Improper Neutralization of Special Elements | |
Weaknesses | CWE-90 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-21T17:48:11.466Z
Updated: 2025-07-21T18:09:07.329Z
Reserved: 2025-06-18T03:55:52.037Z
Link: CVE-2025-52575

Updated: 2025-07-21T18:07:26.410Z

Status : Awaiting Analysis
Published: 2025-07-21T18:15:28.077
Modified: 2025-07-22T13:05:40.573
Link: CVE-2025-52575

No data.