SuiteCRM Cross-Site Scripting Vulnerability

Vulnerability

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in SuiteCRM versions prior to 7.14.1 and 8.8.1. This vulnerability allows attackers to execute JavaScript by altering the HTTP Referer header to include a malicious domain with embedded script code. While the server attempts to block the domain, it inadvertently permits the execution of the JavaScript.

Impact

Exploitation of this vulnerability allows for reflected Cross-Site Scripting, where an attacker can inject and execute malicious JavaScript in the context of the user's browser.

Remediation

Users can upgrade to SuiteCRM versions 7.14.7 or 8.8.1 to address this vulnerability.

Added: Oct 27, 2025, 1:17 PM
Updated: Oct 27, 2025, 1:27 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
6.4
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.