EspoCRM versions 9.3.3 and below contain an authenticated Server-Side Request Forgery (SSRF) vulnerability that allows attackers to bypass internal-host validation by using alternative IPv4 representations such as octal notation. The vulnerability exists in the HostCheck::isNotInternalHost() function, which fails to recognize alternative IP formats, causing validation to incorrectly treat requests to loopback addresses as safe. An authenticated user can exploit this through the /api/v1/Attachment/fromImageUrl endpoint to force the server to make requests to internal services and retrieve the responses as attachments. The vulnerability carries a CVSS score of 4.3 (Medium severity) with a network-based attack vector, low complexity, and requirement for valid user authentication. The impact is limited to confidentiality disclosure, with no integrity or availability impact, as attackers can only read responses from internal resources accessible to the application. The EPSS score of 0.0003 indicates minimal real-world exploitation likelihood compared to other vulnerabilities. There is no evidence of active exploitation in the wild, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and the KEV status is inactive. Community attention appears minimal based on the available data. EspoCRM released version 9.3.4 to address this issue, and organizations should prioritize patching systems running vulnerable versions, particularly in environments where users with API access may pose a risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.3.4CPE matchmatch criteria | cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.