Reflected XSS Vulnerability in SuiteCRM Affects Multiple Versions
CVE-2025-54783
5.1MEDIUM
What is CVE-2025-54783?
SuiteCRM, an open-source Customer Relationship Management application, has a vulnerability that enables attackers to inject malicious JavaScript code via the manipulation of the HTTP Referer header. This occurs on versions up to 7.14.6, where the server's attempt to block arbitrary domains fails, allowing for JavaScript code execution. This vulnerability has been addressed in SuiteCRM version 7.14.7, making it crucial for users to upgrade to safeguard against potential exploits.
Affected Version(s)
SuiteCRM < 7.14.7