SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, SuiteCRM contains an unauthenticated open redirect vulnerability in the WebToLead capture functionality. A user-supplied POST parameter is used as a redirect destination without validation, allowing attackers to redirect victims to arbitrary external websites. This vulnerability allows attackers to abuse the trusted SuiteCRM domain for phishing and social engineering attacks by redirecting users to malicious external websites. Versions 7.15.1 and 8.9.3 patch the issue.
References
| Link | Resource |
|---|---|
| https://docs.suitecrm.com/admin/releases/7.15.x | Release Notes |
| https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-9crg-83cg-wv74 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-03-19 23:16
Updated : 2026-03-24 14:10
NVD link : CVE-2026-29105
Mitre link : CVE-2026-29105
CVE.ORG link : CVE-2026-29105
JSON object : View
Products Affected
suitecrm
- suitecrm
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
