PT-2025-45524 · Suitecrm · Suitecrm

Published

2025-11-04

·

Updated

2025-11-08

·

CVE-2025-64491

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SuiteCRM versions 7.14.7 and below
Description SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Versions 7.14.7 and below are susceptible to unauthenticated reflected Cross-Site Scripting (XSS). Exploitation of this issue could result in full account takeover, potentially achieved by modifying the login form to redirect credentials to an attacker-controlled server. Successful exploitation requires a victim to open a specially crafted malicious link, which could be delivered through methods like phishing or social media.
Recommendations Update to SuiteCRM version 7.14.8 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-13975
CVE-2025-64491
GHSA-PRFM-6667-X3MV

Affected Products

Suitecrm