PT-2026-30472 · Suitecrm · Suitecrm

Mehmet Emiroglu

·

Published

2026-04-05

·

Updated

2026-04-05

·

CVE-2019-25663

CVSS v3.1

7.1

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the email module with malicious parentTab values using boolean-based SQL injection techniques to extract sensitive database information.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2019-25663

Affected Products

Suitecrm