Impact
EspoCRM versions prior to 10.0.6 allow an attacker to skip the second factor of two‑factor authentication when accessing specific routes that do not require authentication. By knowing a 2FA‑enabled user’s username and password, an attacker can complete the login only to the point of the first factor and then read configuration parameters that are not normally exposed. The primary impact is unauthorized disclosure of sensitive configuration data, potentially aiding further attacks.
Affected Systems
The vulnerability affects EspoCRM as distributed by the EspoCRM project. All installations running a version older than 10.0.6 are impacted; newer releases are not susceptible.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in CISA KEV. Based on the description, the attacker must have valid user credentials and can exploit the flaw via unauthenticated routes that bypass the second authentication factor. The risk is therefore limited to confidentiality compromise of configuration settings rather than full system compromise.
OpenCVE Enrichment