CVE-2022-50590

SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the administrator.
Configurations

Configuration 1 (hide)

cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-11-06 20:15

Updated : 2025-11-24 19:05


NVD link : CVE-2022-50590

Mitre link : CVE-2022-50590

CVE.ORG link : CVE-2022-50590


JSON object : View

Products Affected

salesagility

  • suitecrm
CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')