SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.
References
| Link | Resource |
|---|---|
| https://blog.exodusintel.com/2022/06/09/salesagility-suitecrm-export-request-sql-injection-vulnerability/ | Third Party Advisory |
| https://docs.suitecrm.com/admin/releases/7.12.x/#_7_12_6 | Release Notes |
| https://www.vulncheck.com/advisories/suitecrm-sqli-via-export-functionality | Third Party Advisory |
Configurations
History
24 Nov 2025, 19:07
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| First Time |
Salesagility
Salesagility suitecrm |
|
| References | () https://blog.exodusintel.com/2022/06/09/salesagility-suitecrm-export-request-sql-injection-vulnerability/ - Third Party Advisory | |
| References | () https://docs.suitecrm.com/admin/releases/7.12.x/#_7_12_6 - Release Notes | |
| References | () https://www.vulncheck.com/advisories/suitecrm-sqli-via-export-functionality - Third Party Advisory |
06 Nov 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-06 20:15
Updated : 2025-11-24 19:07
NVD link : CVE-2022-50589
Mitre link : CVE-2022-50589
CVE.ORG link : CVE-2022-50589
JSON object : View
Products Affected
salesagility
- suitecrm
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
