216.73.217.172

CVE-2025-64493

· Published 08/11/2025 02:15 · Modified 25/11/2025 17:33

Labels: CVE-2025-64493 2025-11-08CVE-2025-64493CWE-89[email protected]

Essential information

Published
08/11/2025 02:15
Modified
25/11/2025 17:33
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8.6.0 through 8.9.0, there is an authenticated, blind (time-based) SQL-injection inside the appMetadata-operation of the GraphQL-API. This allows extraction of arbitrary data from the database, and does not require administrative access. This issue is fixed in version 8.9.1.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
salesagility / suitecrm cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*

References