id: espocrm-installer info: name: Espocrm Installer author: DhiyaneshDk severity: high description: Espocrm is susceptible to the Installation page exposure due to misconfiguration. classification: cpe: cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: espocrm product: espocrm shodan-query: html:"Welcome to Espocrm" tags: misconfig,espocrm,install,exposure http: - method: GET path: - '{{BaseURL}}/install/' matchers-condition: and matchers: - type: word part: body words: - 'EspoCRM Installation' - type: status status: - 200 # digest: 4b0a00483046022100913d0be83eb660c00f934af36e5b7d9861585f16f762037643f70f143104e66b022100e298f364b2a01ad8b4d58000ddfc08b081999ab764b8c3ea6faf5784e76a93a7:922c64590222798bb761d5b6d8e72950