Home

Description

SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.

PUBLISHED Reserved 2025-11-05 | Published 2025-11-06 | Updated 2025-11-06 | Assigner VulnCheck




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

Default status
unaffected

Any version before 7.12.6
affected

Timeline

2022-06-09:Exodus Intelligence publicly discloses technical details of vulnerability.
2022-05-24:SuiteCRM releases patched version - 7.12.6.

Credits

Exodus Intelligence finder

References

docs.suitecrm.com/admin/releases/7.12.x/ vendor-advisory patch

blog.exodusintel.com/...request-sql-injection-vulnerability/ technical-description

www.vulncheck.com/.../suitecrm-sqli-via-export-functionality third-party-advisory

cve.org (CVE-2022-50589)

nvd.nist.gov (CVE-2022-50589)

Download JSON