Impact
EspoCRM before version 10.0.4 contains a field‑level security bypass in the meeting and call attendees endpoints that allows an authenticated user to read email addresses that should be hidden. By sending a request to the attendees endpoint, an attacker can bypass the intended field‑level protection because the system checks the permissions on the parent event instead of on each attendee record. This results in unauthorized disclosure of private attendee contact information.
Affected Systems
EspoCRM systems running any release prior to 10.0.4 are impacted. The affected product is espocrm:espocrm and the issue is present in all versions below 10.0.4.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability requires an authenticated session to access the affected endpoints. The CVSS score of 8.7 indicates a high severity impact. The absence of an EPSS score and the fact that the flaw is not listed in the CISA KEV catalog suggest that widespread exploitation is unlikely as of the current data. Nevertheless, because the attack path uses legitimate API calls, an attacker with legitimate user credentials can retrieve the hidden emails without triggering obvious alarms, making the risk noteworthy for environments where attendee email privacy is a regulatory or business requirement.
OpenCVE Enrichment