Open redirect in SuiteCRM - CVE-2024-36406
Published: June 10, 2024 / Updated: April 24, 2026
SuiteCRM
SalesAgility
Description
The vulnerability allows a remote attacker to redirect users to an untrusted site.
The vulnerability exists due to url redirection to an untrusted site in the redirect functionality when handling a user-supplied redirect URL. A remote attacker can send a crafted link to redirect users to an untrusted site.
User interaction is required to follow the crafted link.