Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 25 Nov 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Salesagility
Salesagility suitecrm |
|
| CPEs | cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Salesagility
Salesagility suitecrm |
Mon, 10 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Suitecrm
Suitecrm suitecrm |
|
| Vendors & Products |
Suitecrm
Suitecrm suitecrm |
Sat, 08 Nov 2025 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and below allow unauthenticated reflected Cross-Site Scripting (XSS). Successful exploitation could lead to full account takeover, for example by altering the login form to send credentials to an attacker-controlled server. As a reflected XSS issue, exploitation requires the victim to open a crafted malicious link, which can be delivered via phishing, social media, or other communication channels. This issue is fixed in version 7.14.8. | |
| Title | SuiteCRM is vulnerable to unauthenticated reflected XSS through its Login page | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-10T16:45:15.296Z
Reserved: 2025-11-05T19:12:25.102Z
Link: CVE-2025-64491
Updated: 2025-11-10T16:44:54.087Z
Status : Analyzed
Published: 2025-11-08T01:15:39.000
Modified: 2025-11-25T17:33:02.267
Link: CVE-2025-64491
No data.
OpenCVE Enrichment
Updated: 2025-11-10T09:33:32Z