Sploitus

CVE-2025-32390

No indexed exploits for CVE-2025-32390 yet

EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Knowledge Base (KB) articles leads to complete page defacement imitating the login page. Authenticated users with the read knowledge article privilege can browse to the KB article and if they submit their credentials, they get captured in plain text. The vulnerability is allowed by overly permissive HTML editing being allowed on the KB articles. Any authenticated user with the privilege to read KB articles is impacted. In an enterprise with multiple applications, the malicious KB article could be edited to match the login pages of other applications, which would make it useful for credential harvesting against other applications as well. Version 9.0.8 contains a patch for the issue.

Affected products
Espocrm
Espocrm
< 9.0.8
Fix
Available
CVSS 3.1
8.5 HIGH
EPSS
0.3% (24th percentile)
Weakness
CWE-74
NVD status
Analyzed
Published
2025-05-12
CVE-2025-32390 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-32390 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-32390 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.