SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cross Site Scripting (XSS) vulnerability in the email viewer in versions 7.14.0 through 7.14.6. An external attacker could send a prepared message to the inbox of the SuiteCRM-instance. By simply viewing emails as the logged-in user, the payload can be triggered. With that, an attacker is able to run arbitrary actions as the logged-in user - like extracting data, or if it is an admin executing the payload, takeover the instance. This is fixed in versions 7.14.7.
History

Thu, 07 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 07 Aug 2025 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Salesagility
Salesagility suitecrm
Suitecrm
Suitecrm suitecrm
Vendors & Products Salesagility
Salesagility suitecrm
Suitecrm
Suitecrm suitecrm

Thu, 07 Aug 2025 00:45:00 +0000

Type Values Removed Values Added
Description SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cross Site Scripting (XSS) vulnerability in the email viewer in versions 7.14.0 through 7.14.6. An external attacker could send a prepared message to the inbox of the SuiteCRM-instance. By simply viewing emails as the logged-in user, the payload can be triggered. With that, an attacker is able to run arbitrary actions as the logged-in user - like extracting data, or if it is an admin executing the payload, takeover the instance. This is fixed in versions 7.14.7.
Title SuiteCRM is vulnerable to Cross Site Scripting (XSS) through its email viewer
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-07T00:07:07.525Z

Updated: 2025-08-07T13:59:34.417Z

Reserved: 2025-07-29T16:50:28.392Z

Link: CVE-2025-54784

cve-icon Vulnrichment

Updated: 2025-08-07T13:59:22.160Z

cve-icon NVD

Status : Received

Published: 2025-08-07T01:15:26.050

Modified: 2025-08-07T01:15:26.050

Link: CVE-2025-54784

cve-icon Redhat

No data.