SuiteCRM Cross-Site Scripting Vulnerability in Email Viewer
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in the email viewer of SuiteCRM versions 7.14.0 through 7.14.6. This vulnerability allows an external attacker to send a crafted message to a user's inbox. When the email is viewed, the embedded payload is executed. This exploitation enables the attacker to perform actions on behalf of the logged-in user, such as data extraction. If the user has administrative privileges, the attacker could potentially take over the SuiteCRM instance.
Impact
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can execute scripts in the context of the user's session.
Remediation
Users can upgrade to SuiteCRM version 7.14.7 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
