Junglewise Threat Intelligence

CVE-2025-70936: Vtiger CRM reflected XSS in MailManager module

CVE-2025-70936 · Severity: medium · CVSS 5.4 · Published 2026-04-13

Technologies: Vtiger Crm.

Executive brief

Vtiger CRM, a popular open-source platform for managing customer relationships and sales pipelines, contains a security flaw in its MailManager module. An attacker could use this vulnerability to execute malicious scripts in the browser of an authenticated user, potentially leading to unauthorized actions or the theft of session information. This could compromise the integrity of customer data and disrupt business operations for organizations using the affected version.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Vtiger CRM 8.4.0 within the MailManager module. The root cause is improper neutralization of user-controlled input in the '_folder' parameter. An attacker can bypass security filters by using a specially crafted, double URL-encoded payload. When an authenticated user interacts with a malicious link, the payload is reflected and executed in the context of their session. This allows for the execution of arbitrary JavaScript, which can be used to hijack sessions or perform actions on behalf of the user. The vulnerability requires network access and minimal user interaction (clicking a link) by an authenticated user.

Affected products

  • Vtiger CRM 8.4.0

Timeline

  • 2026-04-13: advisory: CVE published by MITRE/NVD

References