SB2026041455 - Insecure configuration in EspoCRM
Published: April 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insecure configuration (CVE-ID: CVE-2025-32385)
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper security configuration in iframe dashlet when rendering a user-defined iframe URL without the sandbox attribute. A remote attacker can trick the victim into specifying a malicious URL to disclose sensitive information.
User interaction is required to specify the crafted URL.
Remediation
Install update from vendor's website.