CVE-2020-37094
EUVD-2020-3100803.02.2026, 22:16
EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized access to administrative user information and privileges.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| espocrm | espocrm | 𝑥 ≤ 5.8.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration