Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in SuiteCRM - CVE-2024-36417
Published: June 10, 2024 / Updated: April 24, 2026
SuiteCRM
SalesAgility
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper neutralization of script-related html tags in a web page in input fields when rendering unverified iframe content. A remote user can inject a malicious iframe to disclose sensitive information.
User interaction is required for exploitation.