Metrics
Affected Vendors & Products
No advisories yet.
Solution
The vulnerabilities have been fixed by the SuiteCRM team in versions 7.14.7 and 8.8.1.
Workaround
No workaround given by the vendor.
Mon, 27 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Scripting (XSS) vulnerability reflected in SuiteCRM v7.14.1. This vulnerability allows an attacker to execute JavaScript code by modifying the HTTP Referer header to include an arbitrary domain with malicious JavaScript code at the end. The server will attempt to block the arbitrary domain but will allow the JavaScript code to execute. | |
| Title | Reflected Cross-Site Scripting (XSS) in SuiteCRM | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-10-27T15:08:15.360Z
Reserved: 2025-04-16T09:57:07.298Z
Link: CVE-2025-41384
Updated: 2025-10-27T15:08:11.150Z
Status : Awaiting Analysis
Published: 2025-10-27T13:15:45.300
Modified: 2025-10-27T13:19:49.063
Link: CVE-2025-41384
No data.
OpenCVE Enrichment
No data.