SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to penetration, privilege escalation, sensitive data exposure, Denial of Service, cryptomining and ransomware. This issue is fixed in version 7.14.7 and 8.8.1.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 07 Aug 2025 07:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Salesagility
Salesagility suitecrm Suitecrm Suitecrm suitecrm |
|
Vendors & Products |
Salesagility
Salesagility suitecrm Suitecrm Suitecrm suitecrm |
Wed, 06 Aug 2025 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to penetration, privilege escalation, sensitive data exposure, Denial of Service, cryptomining and ransomware. This issue is fixed in version 7.14.7 and 8.8.1. | |
Title | SuiteCRM is Vulnerable to PHP Object Injection in Reports | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-06T23:15:16.718Z
Updated: 2025-08-07T14:48:26.266Z
Reserved: 2025-07-29T16:50:28.392Z
Link: CVE-2025-54785

Updated: 2025-08-07T14:48:23.262Z

Status : Received
Published: 2025-08-07T00:15:31.627
Modified: 2025-08-07T00:15:31.627
Link: CVE-2025-54785

No data.