PT-2025-45498 · Suitecrm · Suitecrm

Published

2025-11-04

·

Updated

2025-11-13

·

CVE-2025-64489

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SuiteCRM versions 7.14.7 and prior SuiteCRM versions 8.0.0 through 8.9.0
Description SuiteCRM is a Customer Relationship Management (CRM) software application. A flaw exists where user sessions are not invalidated when an account is deactivated. A user with a deactivated account and an active session can continue to access the application and reactivate their account, bypassing administrative controls and allowing unauthorized persistence.
Recommendations Update to SuiteCRM version 7.14.8 or later. Update to SuiteCRM version 8.9.1 or later.

Exploit

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-13973
CVE-2025-64489
GHSA-J6JG-9JJ3-Q2PH

Affected Products

Suitecrm