SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to penetration, privilege escalation, sensitive data exposure, Denial of Service, cryptomining and ransomware. This issue is fixed in version 7.14.7 and 8.8.1.
History

Thu, 07 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 07 Aug 2025 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Salesagility
Salesagility suitecrm
Suitecrm
Suitecrm suitecrm
Vendors & Products Salesagility
Salesagility suitecrm
Suitecrm
Suitecrm suitecrm

Wed, 06 Aug 2025 23:30:00 +0000

Type Values Removed Values Added
Description SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to penetration, privilege escalation, sensitive data exposure, Denial of Service, cryptomining and ransomware. This issue is fixed in version 7.14.7 and 8.8.1.
Title SuiteCRM is Vulnerable to PHP Object Injection in Reports
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-06T23:15:16.718Z

Updated: 2025-08-07T14:48:26.266Z

Reserved: 2025-07-29T16:50:28.392Z

Link: CVE-2025-54785

cve-icon Vulnrichment

Updated: 2025-08-07T14:48:23.262Z

cve-icon NVD

Status : Received

Published: 2025-08-07T00:15:31.627

Modified: 2025-08-07T00:15:31.627

Link: CVE-2025-54785

cve-icon Redhat

No data.