CVE-2025-52892 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP. In versions 9.1.6 and below, if a user…
Medium CVSS: 4.5

CVE-2025-52892

EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP. In versions 9.1.6 and below, if a user loads Espo in the browser with double slashes (e.g https://domain//#Admin) and the webserver does not strip the double slash, it can cause a corrupted Slim router's cache. This will make the instance unusable until there is a completed rebuild. This is fixed in version 9.1.7.
Vendor
Espocrm
Product
Espocrm
CWE
CWE-444
Yayın Tarihi
2025-08-05 01:15:39
Güncelleme
2025-09-11 17:14:04
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar