#VU125914 Insecure configuration in EspoCRM - CVE-2025-32385
Published: April 15, 2025 / Updated: April 14, 2026
EspoCRM
EspoCRM
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper security configuration in iframe dashlet when rendering a user-defined iframe URL without the sandbox attribute. A remote attacker can trick the victim into specifying a malicious URL to disclose sensitive information.
User interaction is required to specify the crafted URL.