CVE-2025-32385
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2025-32385 is a vulnerability affecting EspoCRM, an open-source Customer Relationship Management software. Before version 9.0.5, the Iframe dashlet in EspoCRM allows users to display iframes with arbitrary URLs, without the implementation of a sandbox attribute. This oversight enables remote pages to open pop-ups outside of the iframe, posing a phishing risk. Attackers could potentially trick users into specifying a malicious URL for the iframe. Additionally, the missing sandbox attribute enables the remote page to send messages to the parent frame, although EspoCRM does not utilize these messages. This vulnerability has been addressed in version 9.0.5.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- EspoCRM