← volver
CVE-2025-52892mediumCWE-444

EspoCRM is vulnerable to access denial through double slash in URI corrupting router cache

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 4.5epss 0.2%
probabilidad de explotación
0.2%top 84% de las CVE
explotación observada
noninguna fuente lo reporta
EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP. In versions 9.1.6 and below, if a user loads Espo in the browser with double slashes (e.g https://domain//#Admin) and the webserver does not strip the double slash, it can cause a corrupted Slim router's cache. This will make the instance unusable until there is a completed rebuild. This is fixed in version 9.1.7.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
Productos afectados
espocrm · espocrm