CVE 8.8 HIGH

SuiteCRM is Vulnerable to Authenticated Time Based Blind SQL Injection_CVE-2025-64492

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0 and below contain a time-based blind SQL Injection vulnerability. This vulnerability allows an authenticated attacker to infer data from the database by measuring response times, potentially leading to the extraction of sensitive information. It is possible for an attacker to enumerate database, table, and column names, extract sensitive data, or escalate privileges. This is fixed in version 8.9.1.

AI Analysis

Time-based blind SQL injection vulnerability allowing authenticated attackers to extract sensitive information by measuring response times.

Basic Information

ID CVE-2025-64492
Source GitHub_M
Published Nov 8, 2025 at 01:07

Affected Product

Vendor SuiteCRM
Product SuiteCRM-Core
Version < 8.9.1
Affected Versions SuiteCRM SuiteCRM-Core < 8.9.1

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor SalesAgility
Product SuiteCRM
Version 8.9.0 and below

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.