Open redirect in SuiteCRM - CVE-2026-29105
Published: April 24, 2026
SuiteCRM
Detailed vulnerability description
The vulnerability allows a remote attacker to redirect users to arbitrary external websites.
The vulnerability exists due to url redirection to an untrusted site in the Leads WebToLead capture functionality when processing a user-supplied POST parameter as a redirect destination. A remote attacker can supply a crafted POST parameter to redirect users to arbitrary external websites.
User interaction is required for a victim to follow the malicious redirect.