CVE-2025-32789

Source
https://cve.org/CVERecord?id=CVE-2025-32789
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-32789.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-32789
Aliases
  • GHSA-3ph3-jcfx-fq53
Published
2025-04-16T21:45:21.625Z
Modified
2026-04-10T05:25:14.109944Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
EspoCRM Allows Potential Disclosure of Sensitive Information in the User Sorting Function
Details

EspoCRM is an Open Source Customer Relationship Management software. Prior to version 9.0.7, users can be sorted by their password hash. This flaw allows an attacker to make assumptions about the hash values of other users stored in the password column of the user table, based on the results of the sorted list of users. Although unlikely, if an attacker knows the hash value of their password, they can change the password and repeat the sorting until the other user's password hash is fully revealed. This issue is patched in version 9.0.7.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200",
        "CWE-203"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32789.json"
}
References

Affected packages

Git / github.com/espocrm/espocrm

Affected ranges

Type
GIT
Repo
https://github.com/espocrm/espocrm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
2.*
2.0.1
2.3.0
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0
2.8.0
2.8.1
2.9.0
3.*
3.0.0
3.1.0
3.2.0
3.3.0
3.4.0
3.4.1
3.4.2
3.5.0
3.6.0
3.6.1
3.7.0
3.7.1
3.8.0
3.9.0
3.9.1
4.*
4.0.0
4.0.0-beta.1
4.0.0-beta.2
4.0.0-beta.3
4.0.0-beta.4
4.0.1
4.0.2
4.0.3
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.3.0
4.3.0-beta.1
4.3.0-beta.2
4.4.0
4.5.0
4.6.0
4.7.0
4.8.0
5.*
5.0.0
5.0.1
5.1.0
5.1.1
5.1.2
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.3.0
5.3.1
5.3.2
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1
5.6.0
5.6.1
5.7.0
5.7.1
5.7.2
5.7.3
5.7.4
5.7.5
5.8.0
5.8.1
5.8.2
5.9.0
5.9.1
5.9.2
6.*
6.0.0
6.0.0-beta1
6.0.0-beta2
6.0.0-beta4
6.0.1
7.*
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.1
7.1.2
7.1.3
7.2.0
7.3.0
7.4.0
7.4.1
7.4.2
7.4.3
8.*
8.0.0
8.0.1
8.0.2
8.1.0
8.2.0
8.4.0
9.*
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5
9.0.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-32789.json"