EspoCRM

EspoCRM is a web application that allows you to see enter and evaluate all your company relationships regardless of the type. People companies projects or opportunities all in an easy and intuitive interface.

Severity Summary:

Critical: 1 High: 6 Medium: 19 Low: 1
Reference
Title
Severity
EspoCRM Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Critical
EspoCRM Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability
High
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability
High
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability
High
EspoCRM Improper Restriction of Excessive Authentication Attempts Vulnerability
High
EspoCRM Improper Neutralization of Formula Elements in a CSV File Vulnerability
High
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability
High
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Server-Side Request Forgery (SSRF) Vulnerability
Medium
EspoCRM Cleartext Transmission of Sensitive Information Vulnerability
Medium
EspoCRM Improper Neutralization of Formula Elements in a CSV File Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Permissions Privileges and Access Controls Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
EspoCRM Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Low