Impact
EspoCRM versions earlier than 10.0.5 contain an insecure direct object reference flaw in the PersonalAccount Service that permits a user with Email Account scope to request the IMAP password of any other user whose Email Account record ID is known. The vulnerability allows a malicious actor to retrieve stored IMAP credentials and consequently gain access to the victim’s mailbox, thereby violating the confidentiality of that mailbox and potentially compromising additional data visible through the email client.
Affected Systems
The affected product is EspoCRM, any deployment of versions prior to 10.0.5. The flaw is present in the PersonalAccount module of the application and is tied to the Email Account scope. Users who are granted Email Account permissions on the system are at risk when the unpatched version is in use.
Risk and Exploitability
The CVSS score is 8.3, indicating high severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack requires an authenticated user with Email Account scope and knowledge of the target’s Email Account record ID. Once these prerequisites are met, the attacker can directly retrieve the IMAP password without further exploitation.
OpenCVE Enrichment