SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows unauthenticated access to meeting data. An unauthenticated actor can view any user's meeting (calendar event) data given their username, related functionality allows user enumeration. This is fixed in versions 7.14.7 and 8.8.1.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 07 Aug 2025 07:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Salesagility
Salesagility suitecrm Suitecrm Suitecrm suitecrm |
|
Vendors & Products |
Salesagility
Salesagility suitecrm Suitecrm Suitecrm suitecrm |
Wed, 06 Aug 2025 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows unauthenticated access to meeting data. An unauthenticated actor can view any user's meeting (calendar event) data given their username, related functionality allows user enumeration. This is fixed in versions 7.14.7 and 8.8.1. | |
Title | SuiteCRM: Legacy iCal service allows unauthenticated access to meeting data | |
Weaknesses | CWE-200 CWE-284 CWE-287 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-06T23:23:00.948Z
Updated: 2025-08-07T14:47:54.710Z
Reserved: 2025-07-29T16:50:28.392Z
Link: CVE-2025-54786

Updated: 2025-08-07T14:47:51.816Z

Status : Received
Published: 2025-08-07T00:15:32.520
Modified: 2025-08-07T00:15:32.520
Link: CVE-2025-54786

No data.