Impact
EspoCRM versions prior to 10.0.6 store the raw contents of data submitted through the public lead capture form in a LeadCaptureLogRecord. When administrators view the log, this data is rendered unescaped, allowing an attacker to inject arbitrary HTML elements. Although the default Content Security Policy in recent deployments prevents the execution of malicious JavaScript, the injection still permits content tampering, potential phishing attempts, and defacement visible to privileged users.
Affected Systems
EspoCRM, all releases before version 10.0.6. The vulnerability applies to any instance that has the public lead capture form enabled, regardless of the specific deployment configuration.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, indicating moderate severity. No EPSS score is available, and the flaw is not listed in the CISAV catalog. The most straightforward attack is a web request to the exposed lead capture endpoint, which requires no authentication and can be performed by any Internet user. Because the input is stored and later displayed without proper escaping, the risk is limited to defacement or phishing rather than full code execution. However, the ease of exploitation and potential for persistent malicious content makes the attack vector significant for affected systems.
OpenCVE Enrichment