Arbitrary User Creation Vulnerability in EspoCRM by EspoCRM
CVE-2025-59428
What is CVE-2025-59428?
EspoCRM, an open-source customer relationship management application, contains a vulnerability that permits the creation of arbitrary user accounts, including those with administrative privileges. This issue arises from a synergy of stored SVG injection and insufficient CSRF protection in versions prior to 9.1.9. Attackers with Knowledge Base edit rights can deliver a malicious SVG link in an article's body. When an authenticated user interacts with this link, they may unintentionally execute a CSRF request against the api/v1/User endpoint. If the user enters their credentials at the resulting attacker-controlled page, an unauthorized account is established, endowed with privileges dictated by the CSRF request payload. This critical vulnerability has been rectified in version 9.1.9.
Affected Version(s)
espocrm < 9.1.9