PT-2025-45525 · Suitecrm · Suitecrm

Published

2025-09-04

·

Updated

2025-12-17

·

CVE-2025-64492

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SuiteCRM versions 8.0.0 through 8.9.0
Description SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A time-based blind SQL Injection flaw exists in versions 8.9.0 and below. This issue allows an authenticated attacker to potentially extract sensitive information from the database by observing response times. An attacker could enumerate database, table, and column names, extract data, or escalate privileges. SQL injection occurs when an attacker can manipulate a database query through crafted input, potentially leading to unauthorized access or data leakage. Over 1000 instances of SuiteCRM were identified in the Russian internet space.
Recommendations Update SuiteCRM to version 8.9.1.

Exploit

Fix

RCE

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-10914
CVE-2025-64492
GHSA-54M4-4P54-J8HP

Affected Products

Suitecrm