Improper Neutralization of Special Elements in Output Used by a Downstream Component in EspoCRM - CVE-2025-32390
Published: April 23, 2026
EspoCRM
Detailed vulnerability description
The vulnerability allows a remote user to capture credentials and take over accounts.
The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in knowledge base articles when rendering user-supplied HTML content. A remote user can create a crafted article that imitates a login page to capture credentials and take over accounts.
Exploitation requires the ability to create articles, and user interaction is required for a victim to open the crafted article and submit credentials.