SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.
References
| Link | Resource |
|---|---|
| https://blog.exodusintel.com/2022/06/09/salesagility-suitecrm-export-request-sql-injection-vulnerability/ | Third Party Advisory |
| https://docs.suitecrm.com/admin/releases/7.12.x/#_7_12_6 | Release Notes |
| https://www.vulncheck.com/advisories/suitecrm-sqli-via-export-functionality | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-11-06 20:15
Updated : 2025-11-24 19:07
NVD link : CVE-2022-50589
Mitre link : CVE-2022-50589
CVE.ORG link : CVE-2022-50589
JSON object : View
Products Affected
salesagility
- suitecrm
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
