Security Advisory

CVE-2025-64493

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-11-08 01:16:22
Last updated 2025-11-10 16:39:27
Assigner GitHub_M
CVSS score 6.5
State PUBLISHED

Description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8.6.0 through 8.9.0, there is an authenticated, blind (time-based) SQL-injection inside the appMetadata-operation of the GraphQL-API. This allows extraction of arbitrary data from the database, and does not require administrative access. This issue is fixed in version 8.9.1.