Arbitrary User Creation Vulnerability in EspoCRM by EspoCRM
CVE-2025-59428

5.4MEDIUM

Key Information:

Vendor

Espocrm

Status
Vendor
CVE Published:
14 October 2025

What is CVE-2025-59428?

EspoCRM, an open-source customer relationship management application, contains a vulnerability that permits the creation of arbitrary user accounts, including those with administrative privileges. This issue arises from a synergy of stored SVG injection and insufficient CSRF protection in versions prior to 9.1.9. Attackers with Knowledge Base edit rights can deliver a malicious SVG link in an article's body. When an authenticated user interacts with this link, they may unintentionally execute a CSRF request against the api/v1/User endpoint. If the user enters their credentials at the resulting attacker-controlled page, an unauthorized account is established, endowed with privileges dictated by the CSRF request payload. This critical vulnerability has been rectified in version 9.1.9.

Affected Version(s)

espocrm < 9.1.9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.