PT-2025-32317 · Suitecrm · Suitecrm

·

CVE-2025-54787

·

Published

2025-08-07

·

Updated

2025-08-12

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SuiteCRM version 7.14.6
Description SuiteCRM is an open-source Customer Relationship Management (CRM) software application. A vulnerability exists that allows unauthenticated downloads of any file from the upload-directory, provided the file is named using an ID (e.g., attachments). An unauthenticated attacker could download internal files by discovering a valid file-ID. Valid IDs could be brute-forced, although this may be time-consuming as the file-IDs are typically UUIDs.
Recommendations Upgrade to SuiteCRM version 7.14.7 or later.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-54787
GHSA-8R72-224Q-G9FV

Affected Products

Suitecrm