Reflected Cross-Site Scripting (XSS) in SuiteCRM
Vulnerability Description
Cross-Site Scripting (XSS) vulnerability reflected in SuiteCRM v7.14.1. This vulnerability allows an attacker to execute JavaScript code by modifying the HTTP Referer header to include an arbitrary domain with malicious JavaScript code at the end. The server will attempt to block the arbitrary domain but will allow the JavaScript code to execute.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41384
Credits & Attribution
No credits recorded in the NVD database.
References
More from SuiteCRM
View All →Affected Vendor
SuiteCRM
View all reports →