Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-14351

EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at a time using specially crafted api/v1/User?filterList filters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.7%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 4.0
Products affected by CVE-2019-14351
  • Espocrm » Espocrm » Version: 5.6.4
    cpe:2.3:a:espocrm:espocrm:5.6.4


Contact Us

Shodan ® - All rights reserved