Reflected Cross-Site Scripting Vulnerability in SuiteCRM by SuiteCRM
CVE-2025-64491
What is CVE-2025-64491?
SuiteCRM, an open-source Customer Relationship Management software, is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability in versions up to 7.14.7. This flaw allows attackers to execute malicious scripts in the context of a user's browser, which can lead to severe consequences such as unauthorized account access. Attackers can exploit this vulnerability by enticing users to click on a specially crafted link that contains malicious code. Once executed, the attacker could manipulate the login form to capture sensitive credentials, redirecting them to their server. The issue has been addressed in SuiteCRM version 7.14.8.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SuiteCRM < 7.14.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
