SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cross Site Scripting (XSS) vulnerability in the email viewer in versions 7.14.0 through 7.14.6. An external attacker could send a prepared message to the inbox of the SuiteCRM-instance. By simply viewing emails as the logged-in user, the payload can be triggered. With that, an attacker is able to run arbitrary actions as the logged-in user - like extracting data, or if it is an admin executing the payload, takeover the instance. This is fixed in versions 7.14.7.
References
Link | Resource |
---|---|
https://docs.suitecrm.com/admin/releases/7.14.x/#_7_14_7 | Release Notes |
https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-vg8q-xcq5-mh3p | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
12 Aug 2025, 20:55
Type | Values Removed | Values Added |
---|---|---|
First Time |
Salesagility suitecrm
Salesagility |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
References | () https://docs.suitecrm.com/admin/releases/7.14.x/#_7_14_7 - Release Notes | |
References | () https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-vg8q-xcq5-mh3p - Vendor Advisory | |
Summary | (es) SuiteCRM es una aplicación de software de gestión de relaciones con clientes (CRM) de código abierto y lista para empresas. Existe una vulnerabilidad de Cross-site scripting (XSS) en el visor de correo electrónico de las versiones 7.14.0 a 7.14.6. Un atacante externo podría enviar un mensaje preparado a la bandeja de entrada de la instancia de SuiteCRM. Simplemente viendo los correos electrónicos como el usuario conectado, se puede activar el payload. Con esto, un atacante puede ejecutar acciones arbitrarias como el usuario conectado, como extraer datos o, si es un administrador quien ejecuta el payload, tomar el control de la instancia. Esto se solucionó en la versión 7.14.7. | |
CPE | cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:* |
07 Aug 2025, 21:26
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
07 Aug 2025, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-07 01:15
Updated : 2025-08-12 20:55
NVD link : CVE-2025-54784
Mitre link : CVE-2025-54784
CVE.ORG link : CVE-2025-54784
JSON object : View
Products Affected
salesagility
- suitecrm
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')