CVE-2024-24818

EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim to malicious page that could lead to credential stealing or another attack. This vulnerability is fixed in 8.1.2.
Configurations

No configuration.

History

No history.

Information

Published : 2024-03-21 02:52

Updated : 2024-03-21 12:58


NVD link : CVE-2024-24818

Mitre link : CVE-2024-24818

CVE.ORG link : CVE-2024-24818


JSON object : View

Products Affected

No product.

CWE
CWE-610

Externally Controlled Reference to a Resource in Another Sphere