SuiteCRM Cross-Site Scripting Vulnerability
Vulnerability
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in SuiteCRM versions prior to 7.14.1 and 8.8.1. This vulnerability allows attackers to execute JavaScript by altering the HTTP Referer header to include a malicious domain with embedded script code. While the server attempts to block the domain, it inadvertently permits the execution of the JavaScript.
Impact
Exploitation of this vulnerability allows for reflected Cross-Site Scripting, where an attacker can inject and execute malicious JavaScript in the context of the user's browser.
Remediation
Users can upgrade to SuiteCRM versions 7.14.7 or 8.8.1 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
