PT-2025-45364 · Suitecrm · Suitecrm

·

CVE-2022-50589

·

Published

2022-03-02

·

Updated

2025-11-28

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SuiteCRM versions prior to 7.12.6
Description SuiteCRM’s export functionality has a SQL injection issue due to a failure to sanitize SQL query structure when processing the uid parameter. Successful exploitation could allow a remote, unauthenticated attacker to execute arbitrary code.
Recommendations Update to SuiteCRM version 7.12.6 or later.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13971
CVE-2022-50589

Affected Products

Suitecrm