SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through 8.9.0 8.0.0-beta.1, an attacker can craft a malicious call_id that alters the logic of the SQL query or injects arbitrary SQL. An attack can lead to unauthorized data access and data ex-filtration, complete database compromise, and other various issues. This issue is fixed in versions 7.14.8 and 8.9.1.
Metrics
Affected Vendors & Products
References
History
Sat, 08 Nov 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through 8.9.0 8.0.0-beta.1, an attacker can craft a malicious call_id that alters the logic of the SQL query or injects arbitrary SQL. An attack can lead to unauthorized data access and data ex-filtration, complete database compromise, and other various issues. This issue is fixed in versions 7.14.8 and 8.9.1. | |
| Title | SuiteCRM: Authenticated SQL Injection Possible in Reschedule Call Module | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-11-07T23:59:46.011Z
Updated: 2025-11-07T23:59:46.011Z
Reserved: 2025-11-05T19:12:25.102Z
Link: CVE-2025-64488
No data.
Status : Received
Published: 2025-11-08T00:15:36.313
Modified: 2025-11-08T00:15:36.313
Link: CVE-2025-64488
No data.