MEDIUM
Reflected Cross-Site Scripting (XSS) in SuiteCRM
Published Oct 27, 2025
5.1
MEDIUMCVSS 4.0
EPSS 0.19%
Description
Cross-Site Scripting (XSS) vulnerability reflected in SuiteCRM v7.14.1. This vulnerability allows an attacker to execute JavaScript code by modifying the HTTP Referer header to include an arbitrary domain with malicious JavaScript code at the end. The server will attempt to block the arbitrary domain but will allow the JavaScript code to execute.
Affected products
-
- Version versions prior to 7.14.1 and prior to 8.8.1StatusaffectedConstraints-
- Version
- 7.14.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The vulnerabilities have been fixed by the SuiteCRM team in versions 7.14.7 and 8.8.1.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-36178 Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso/reflected-cross-site-scripting-xss-suitecrm Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-36178 | Advisory | |
| https://www.incibe.es/en/incibe-cert/notices/aviso/reflected-cross-site-scripting-xss-suitecrm | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Oct 27, 2025
Updated Oct 27, 2025
Reserved Apr 16, 2025
Link CVE-2025-41384
CISA Vulnrichment
Updated Oct 27, 2025
ENISA EUVD
EUVD-2025-36178 Assigner INCIBE
Published Oct 27, 2025
Updated Oct 27, 2025
Exploited since n/a
Link EUVD-2025-36178