Access Control Flaw in SuiteCRM Affects Multiple User Roles
CVE-2025-64490
What is CVE-2025-64490?
SuiteCRM, a popular open-source CRM software, contains a vulnerability that allows low-privileged users to access and manipulate work items through the Resource Calendar and project screens, despite strict role management settings that are intended to restrict access. This issue arises from inconsistent enforcement of access control mechanisms across various modules, potentially leading to unauthorized exposure and alteration of sensitive data. The vulnerability is addressed in later versions, ensuring robust access control management.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SuiteCRM < 7.14.8 < 7.14.8
SuiteCRM >= 8.0.0-beta.1, < 8.9.1 < 8.0.0-beta.1, 8.9.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
