CVE-2022-50589

SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*

History

24 Nov 2025, 19:07

Type Values Removed Values Added
CPE cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Salesagility
Salesagility suitecrm
References () https://blog.exodusintel.com/2022/06/09/salesagility-suitecrm-export-request-sql-injection-vulnerability/ - () https://blog.exodusintel.com/2022/06/09/salesagility-suitecrm-export-request-sql-injection-vulnerability/ - Third Party Advisory
References () https://docs.suitecrm.com/admin/releases/7.12.x/#_7_12_6 - () https://docs.suitecrm.com/admin/releases/7.12.x/#_7_12_6 - Release Notes
References () https://www.vulncheck.com/advisories/suitecrm-sqli-via-export-functionality - () https://www.vulncheck.com/advisories/suitecrm-sqli-via-export-functionality - Third Party Advisory

06 Nov 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-06 20:15

Updated : 2025-11-24 19:07


NVD link : CVE-2022-50589

Mitre link : CVE-2022-50589

CVE.ORG link : CVE-2022-50589


JSON object : View

Products Affected

salesagility

  • suitecrm
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')