SB2025072430 - Multiple vulnerabilities in EspoCRM



SB2025072430 - Multiple vulnerabilities in EspoCRM

Published: July 24, 2025 Updated: April 23, 2026

Security Bulletin ID SB2025072430
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) LDAP injection (CVE-ID: CVE-2025-52575)

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to improper input validation when processing DLAP queries. A remote attacker can send a specially crafted LDAP query to the application, manipulate the filter and gain access to sensitive information on the system.


2) Input validation error (CVE-ID: CVE-2025-52892)

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper input handling in the Slim router cache when processing a URI containing a double slash. A remote privileged user can load the application in a browser with a double-slash URI to cause a denial of service.

The issue occurs if the web server does not strip the double slash, and user interaction is required to load the crafted URI.


Remediation

Install update from vendor's website.