CVE-2024-24818: EspoCRM weakness in "Forgot password"
Published Feb 29, 2024
·Updated
EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim to malicious page that could lead to credential stealing or another attack. This vulnerability is fixed in 8.1.2.
Affected Software
2 affected components
EspoCRM EspoCRM<8.1.2
EspoCRM EspoCRM<8.1.2
Remediation
Event History
Feb 29, 2024
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Mar 21, 2024
Data Sourced
via NVD·02:52 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24818?
CVE-2024-24818 is considered a high severity vulnerability due to the potential for credential stealing attacks.
2
How do I fix CVE-2024-24818?
To fix CVE-2024-24818, upgrade EspoCRM to version 8.1.2 or above.
3
What does CVE-2024-24818 exploit?
CVE-2024-24818 exploits the 'Password Change' page by allowing attackers to inject arbitrary IPs or domains.
4
What are the risks associated with CVE-2024-24818?
The risks associated with CVE-2024-24818 include potential redirects to malicious sites leading to credential theft.
5
Which versions of EspoCRM are affected by CVE-2024-24818?
CVE-2024-24818 affects versions of EspoCRM prior to 8.1.2.