Sploitus

CVE-2025-52575

No indexed exploits for CVE-2025-52575 yet

EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulnerable to blind LDAP Injection when LDAP authentication is enabled. A remote, unauthenticated attacker can manipulate LDAP queries by injecting crafted input containing wildcard characters (e.g., *). This may allow the attacker to bypass authentication controls, enumerate valid usernames, or retrieve sensitive directory information depending on the LDAP server configuration. This was fixed in version 9.1.7.

Affected products
Espocrm
Espocrm
< 9.1.7
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
0.7% (50th percentile)
Weakness
CWE-90
NVD status
Analyzed
Published
2025-07-21
CVE-2025-52575 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-52575 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-52575 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.