CVE-2026-33733
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template manag
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled name and scope values and pass them into template path construction without normalization or traversal filtering. As a result, an authenticated admin can use ../ sequences to escape the intended template directory and read, create, overwrite, or delete arbitrary files that resolve to body.tpl or subject.tpl under the web application user's filesystem permissions.
Version 9.3.4 fixes the issue.
HIGH · CVSS 7.2
EPSS 0.00155
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0