SQL Injection Vulnerability in SuiteCRM Affects Multiple Versions
CVE-2025-64488

8.6HIGH

Key Information:

Vendor

Suitecrm

Status
Vendor
CVE Published:
7 November 2025

What is CVE-2025-64488?

SuiteCRM, an open-source Customer Relationship Management software, is susceptible to an SQL injection vulnerability in versions 7.14.7 and below, as well as 8.0.0-beta.1 through 8.9.0. An attacker could exploit this vulnerability by sending a malicious call_id, which manipulates the SQL query logic or injects arbitrary SQL commands. This exploitation can result in unauthorized access to sensitive data, potential data ex-filtration, and a complete database compromise. The issue has been resolved in updates 7.14.8 and 8.9.1. For more detailed technical guidance, please refer to the official advisories.

Affected Version(s)

SuiteCRM >= 8.0.0-beta.1, < 8.9.1 < 8.0.0-beta.1, 8.9.1

SuiteCRM < 7.14.8 < 7.14.8

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.