SuiteCRM Open Redirect Vulnerability in WebToLead Capture Functionality

Vulnerability

An unauthenticated open redirect vulnerability has been identified in SuiteCRM versions prior to 7.15.1 and 8.9.3. The issue arises in the WebToLead capture functionality, where a user-supplied POST parameter is used as a redirect destination without proper validation. This flaw allows attackers to redirect victims to arbitrary external websites, potentially leading to phishing and social engineering attacks that exploit the trusted SuiteCRM domain.

Impact

Exploitation of this vulnerability could be used for phishing and social engineering attacks, redirecting users to malicious external websites while masking the threat under the trusted SuiteCRM domain.

Remediation

Users can upgrade to SuiteCRM versions 7.15.1 or 8.9.3 to address this vulnerability.

Added: Mar 19, 2026, 11:26 PM
Updated: Mar 19, 2026, 11:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.2
exploitability
6.2
remediation
0.0
relevance
4.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.