CRITICAL🇵🇱 Wersja polska

CVE-2022-50589

CVSS 9.3v4.0pub. 2025-11-06upd. 2025-11-24

SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.

🤖 AI Analysis
How it works

An attacker sends a specially crafted export request, injecting malicious SQL code into the 'uid' parameter without needing to have any account in the system. The application does not properly validate or sanitize this value before passing it to the database query. Successful exploitation of a CWE-89 class vulnerability (SQL injection) leads to privilege escalation at the database level, and as a result to the execution of arbitrary code on the server (RCE).

Impact

An unauthenticated attacker can gain full control over the application server through remote code execution of arbitrary code, as well as gain access to all data stored in the database — including customer data and business information.

Mitigation & patch

SuiteCRM should be immediately updated to version 7.12.6 or newer, according to the information in the official release notes from the vendor (https://docs.suitecrm.com/admin/releases/7.12.x/#_7_12_6). Until the patch is implemented, it is recommended to restrict network access to data export functions at the firewall or web server level.

Who is affected

Salesagility SuiteCRM in versions earlier than 7.12.6

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Salesagility Suitecrm

    APP
    Salesagility
    < 7.12.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCESQLiAuth Bypass
CWE
References

Related vulnerabilities

CVE-2024-36411CRITICAL9.6PL ✓same product

SQL Injection w SuiteCRM — kontroler EmailUIAjax displayView

CVE-2024-36410CRITICAL9.6PL ✓same product

SQL Injection w SuiteCRM — kontroler EmailUIAjax messages count

CVE-2024-36408CRITICAL9.6PL ✓same product

SQL Injection w kontrolerze Alerts aplikacji SuiteCRM

CVE-2024-36409CRITICAL9.6PL ✓same product

SQL Injection w SuiteCRM — punkt wejścia danych drzewa

CVE-2024-36412CRITICAL10.0PL ✓same product

SQL injection w SuiteCRM poprzez punkt wejścia odpowiedzi na zdarzenia