PT-2025-45524 · Suitecrm · Suitecrm
Published
2025-11-04
·
Updated
2025-11-08
·
CVE-2025-64491
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SuiteCRM versions 7.14.7 and below
Description
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Versions 7.14.7 and below are susceptible to unauthenticated reflected Cross-Site Scripting (XSS). Exploitation of this issue could result in full account takeover, potentially achieved by modifying the login form to redirect credentials to an attacker-controlled server. Successful exploitation requires a victim to open a specially crafted malicious link, which could be delivered through methods like phishing or social media.
Recommendations
Update to SuiteCRM version 7.14.8 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suitecrm