SuiteCRM Cross-Site Scripting Vulnerability in Email Viewer

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the email viewer of SuiteCRM versions 7.14.0 through 7.14.6. This vulnerability allows an external attacker to send a crafted message to a user's inbox. When the email is viewed, the embedded payload is executed. This exploitation enables the attacker to perform actions on behalf of the logged-in user, such as data extraction. If the user has administrative privileges, the attacker could potentially take over the SuiteCRM instance.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where an attacker can execute scripts in the context of the user's session.

Remediation

Users can upgrade to SuiteCRM version 7.14.7 to address this vulnerability.

Added: Aug 7, 2025, 1:25 AM
Updated: Aug 7, 2025, 1:25 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.