SuiteCRM Blind Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in SuiteCRM versions prior to 7.15.1 and 8.9.3. The issue arises because the return_id request parameter is directly copied into an HTML tag attribute as an event handler, enclosed in double quotation marks. This vulnerability allows an attacker with admin privileges to inject advanced malicious payloads, potentially chaining them with other attack vectors like Cross-Site Request Forgery (CSRF) to act on behalf of the victim. Exploitation could also involve redirecting victims to a malicious website, defacing page content, or, in cases of improper httpOnly cookie flag management, stealing session cookies for session hijacking.

Impact

Exploitation of this vulnerability could lead to blind cross-site scripting, with the potential for session hijacking if the httpOnly cookie flag is misconfigured.

Remediation

Users are advised to upgrade to SuiteCRM versions 7.15.1 or 8.9.3. Additionally, implementing a Content Security Policy (CSP) header can help mitigate XSS vulnerabilities.

Added: Mar 19, 2026, 11:26 PM
Updated: Mar 19, 2026, 11:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.8
exploitability
3.9
remediation
0.0
relevance
4.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.