Description
EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized access to administrative user information and privileges.
Problem types
Authorization Bypass Through User-Controlled Key
Product status
Credits
Besim ALTINOK, İsmail BOZKURT
References
www.exploit-db.com/exploits/48376 (ExploitDB-48376)
www.espocrm.com (EspoCRM Official Vendor Homepage)
www.vulncheck.com/advisories/espocrm-privilege-escalation (VulnCheck Advisory: EspoCRM 5.8.5 - Privilege Escalation)