SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in the backend database, leading to SQL injection. This can have wide-reaching implications on confidentiality, integrity, and availability, as database data can be retrieved, modified, or removed entirely. This issue is fixed in version 7.14.7.
History

Thu, 07 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 07 Aug 2025 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Salesagility
Salesagility suitecrm
Suitecrm
Suitecrm suitecrm
Vendors & Products Salesagility
Salesagility suitecrm
Suitecrm
Suitecrm suitecrm

Thu, 07 Aug 2025 00:00:00 +0000

Type Values Removed Values Added
Description SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in the backend database, leading to SQL injection. This can have wide-reaching implications on confidentiality, integrity, and availability, as database data can be retrieved, modified, or removed entirely. This issue is fixed in version 7.14.7.
Title SuiteCRM: Authenticated Blind SQL Injection in InboundEmail module
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-06T23:48:55.847Z

Updated: 2025-08-07T14:45:17.480Z

Reserved: 2025-07-29T16:50:28.393Z

Link: CVE-2025-54788

cve-icon Vulnrichment

Updated: 2025-08-07T14:45:14.940Z

cve-icon NVD

Status : Received

Published: 2025-08-07T00:15:32.697

Modified: 2025-08-07T00:15:32.697

Link: CVE-2025-54788

cve-icon Redhat

No data.