CVE-2025-52575 | EspoCRM up to 9.1.6 ldap injection (GHSA-rjm8-77fr-4f3v)
A vulnerability, which was classified as critical, was found in EspoCRM up to 9.1.6. Affected is an unknown function. The manipulation leads to ldap injection.
This vulnerability is traded as CVE-2025-52575. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.