CVE-2025-32390 describes an HTML Injection vulnerability in EspoCRM versions prior to 9.0.8, allowing authenticated users with read privileges to deface Knowledge Base articles and create convincing fake login pages. This high-severity flaw (CVSS 8.5) enables credential harvesting, as submitted credentials are captured in plain text. The attack is network-based with low complexity and requires low privileges, impacting confidentiality significantly. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.0.8CPE matchmatch criteria | cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.