PT-2025-32235 · Suitecrm · Suitecrm

Parnuski

·

Published

2025-08-06

·

Updated

2025-08-14

·

CVE-2025-54788

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 7.14.7
Description SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The InboundEmail module allows the arbitrary execution of queries in the backend database, leading to SQL injection. This can have wide-reaching implications on confidentiality, integrity, and availability, as database data can be retrieved, modified, or removed entirely.
Recommendations Update SuiteCRM to version 7.14.7.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-09474
CVE-2025-54788
GHSA-V3M9-8WG7-C72X

Affected Products

Suitecrm