Description
EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account scope access to retrieve other users' IMAP passwords. Attackers who know a victim's Email Account record ID can request that record to steal stored IMAP credentials and access the victim's mailbox.
Related CPE's
Could not find any relations
References
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
7.7 · High
Information
Source identifier
Vulnerability status
Deferred
Published
2026-10-08T15:17:35.913Z
17 hours agoLast modified
2026-10-08T18:17:15.000Z
14 hours ago