PT-2025-32317 · Suitecrm · Suitecrm

Paul1278

·

Published

2025-08-07

·

Updated

2025-08-12

·

CVE-2025-54787

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SuiteCRM version 7.14.6
Description SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability exists that allows unauthenticated downloads of any file from the upload-directory, provided the file is named using an ID (e.g., attachments). An unauthenticated attacker could download internal files by discovering a valid file-ID. Valid IDs could be brute-forced, although this may be time-consuming as the file-IDs are typically UUIDs.
Recommendations Upgrade to SuiteCRM version 7.14.7 or later.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-54787
GHSA-8R72-224Q-G9FV

Affected Products

Suitecrm