HIGH
SuiteCRM: Authenticated SQL Injection Possible in Reschedule Call Module
Published Nov 7, 2025
8.6
HIGHCVSS 4.0
EPSS 0.43%
Description
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through 8.9.0 8.0.0-beta.1, an attacker can craft a malicious call_id that alters the logic of the SQL query or injects arbitrary SQL. An attack can lead to unauthorized data access and data ex-filtration, complete database compromise, and other various issues. This issue is fixed in versions 7.14.8 and 8.9.1.
Affected products
-
- Version < 7.14.8StatusaffectedConstraints-
- Version >= 8.0.0-beta.1, < 8.9.1StatusaffectedConstraints-
- Version
OR
- < 7.14.8
- ≥ 8.0.0 · ≤ 8.9.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-38332 Advisory
- https://github.com/SuiteCRM/SuiteCRM-Core/commit/30277cfe69755f7360a23d4805e06a5c38f14131 x_refsource_MISCPatch
- https://github.com/SuiteCRM/SuiteCRM/commit/40da2845a170832a4e9e9fa0ebe731f8c34de42d x_refsource_MISCPatch
- https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-5v53-v44q-ww2c x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-38332 | Advisory | |
| https://github.com/SuiteCRM/SuiteCRM-Core/commit/30277cfe69755f7360a23d4805e06a5c38f14131 | x_refsource_MISCPatch | |
| https://github.com/SuiteCRM/SuiteCRM/commit/40da2845a170832a4e9e9fa0ebe731f8c34de42d | x_refsource_MISCPatch | |
| https://github.com/SuiteCRM/SuiteCRM/security/advisories/GHSA-5v53-v44q-ww2c | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Nov 7, 2025
Updated Nov 13, 2025
Reserved Nov 5, 2025
Link CVE-2025-64488
CISA Vulnrichment
Updated Nov 13, 2025
ENISA EUVD
EUVD-2025-38332 Assigner GitHub_M
Published Nov 7, 2025
Updated Nov 13, 2025
Exploited since n/a
Link EUVD-2025-38332