CVE-2025-64488 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through…
High CVSS: 8.6

CVE-2025-64488

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through 8.9.0 8.0.0-beta.1, an attacker can craft a malicious call_id that alters the logic of the SQL query or injects arbitrary SQL. An attack can lead to unauthorized data access and data ex-filtration, complete database compromise, and other various issues. This issue is fixed in versions 7.14.8 and 8.9.1.
Vendor
Salesagility
Product
Suitecrm
CWE
CWE-89
Yayın Tarihi
2025-11-08 00:15:36
Güncelleme
2025-11-25 17:29:30
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar