Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23893 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cross Site Scripting (XSS) vulnerability in the email viewer in versions 7.14.0 through 7.14.6. An external attacker could send a prepared message to the inbox of the SuiteCRM-instance. By simply viewing emails as the logged-in user, the payload can be triggered. With that, an attacker is able to run arbitrary actions as the logged-in user - like extracting data, or if it is an admin executing the payload, takeover the instance. This is fixed in versions 7.14.7. |
Tue, 12 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 07 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 07 Aug 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Salesagility
Salesagility suitecrm Suitecrm Suitecrm suitecrm |
|
| Vendors & Products |
Salesagility
Salesagility suitecrm Suitecrm Suitecrm suitecrm |
Thu, 07 Aug 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a Cross Site Scripting (XSS) vulnerability in the email viewer in versions 7.14.0 through 7.14.6. An external attacker could send a prepared message to the inbox of the SuiteCRM-instance. By simply viewing emails as the logged-in user, the payload can be triggered. With that, an attacker is able to run arbitrary actions as the logged-in user - like extracting data, or if it is an admin executing the payload, takeover the instance. This is fixed in versions 7.14.7. | |
| Title | SuiteCRM is vulnerable to Cross Site Scripting (XSS) through its email viewer | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-07T13:59:34.417Z
Reserved: 2025-07-29T16:50:28.392Z
Link: CVE-2025-54784
Updated: 2025-08-07T13:59:22.160Z
Status : Analyzed
Published: 2025-08-07T01:15:26.050
Modified: 2025-08-12T20:55:36.633
Link: CVE-2025-54784
No data.
OpenCVE Enrichment
Updated: 2025-08-07T07:04:40Z
EUVD