Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-33733

HIGH NVD
CVSS Score 7.2
Severity HIGH
Published Apr 22, 2026
Vendor unknown

Description

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled `name` and `scope` values and pass them into template path construction without normalization or traversal filtering. As a result, an authenticated admin can use `../` sequences to escape the intended template directory and read, create, overwrite, or delete arbitrary files that resolve to `body.tpl` or `subject.tpl` under the web application user's filesystem permissions. Version 9.3.4 fixes the issue.

References