CVE-2020-37094

Szczegóły podatności CVE.
Aktualizacja: 04.03.2026, 01:54 (CET)
non-KEV CVSS 9.8 EPSS 0.0009 Score 29.45

EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized access to administrative user information and privileges.

Źródła

ŹródłoLinkUwagi
NVD (NIST)https://nvd.nist.gov/vuln/detail/CVE-2020-37094Karta CVE w NVD
CISA KEVhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-37094Wyszukiwanie CVE w KEV
FIRST EPSShttps://api.first.org/data/v1/epss?cve=CVE-2020-37094API EPSS dla CVE
disclosure@vulncheck.comhttps://www.espocrm.comProduct
disclosure@vulncheck.comhttps://www.exploit-db.com/exploits/48376Exploit, VDB Entry
disclosure@vulncheck.comhttps://www.vulncheck.com/advisories/espocrm-privilege-escalationThird Party Advisory