CVE-2025-54788
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions an
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in the backend database, leading to SQL injection. This can have wide-reaching implications on confidentiality, integrity, and availability, as database data can be retrieved, modified, or removed entirely.
This issue is fixed in version 7.14.7.
HIGH · CVSS 8.8
EPSS 0.00395
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0