CVE-2024-24818
5.9
MEDIUM
CVSS 3.1
EPSS 0.61%
Description
EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim to malicious page that could lead to credential stealing or another attack. This vulnerability is fixed in 8.1.2.
How to fix CVE-2024-24818
To remediate CVE-2024-24818, upgrade the affected package to a fixed version below.
- Bitnami/espocrm—upgrade to 8.1.2 or later
Is CVE-2024-24818 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 8.1.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L |