Cross-site scripting in SuiteCRM - CVE-2025-64491
Published: April 24, 2026
SuiteCRM
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the victim's browser.
The vulnerability exists due to cross-site scripting in the login page when handling a crafted malicious link. A remote attacker can send a specially crafted link to execute arbitrary JavaScript in the victim's browser.
User interaction is required to open a crafted malicious link.