Improper Neutralization of Alternate XSS Syntax in SuiteCRM - CVE-2024-36413
Published: June 10, 2024 / Updated: April 24, 2026
SuiteCRM
SalesAgility
Description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of alternate XSS syntax in the import module error view when handling user-generated content. A remote user can inject malicious script into content viewed by other users to execute arbitrary script in a victim's browser.
User interaction is required to view the crafted content.