Time-Based Blind SQL Injection in SuiteCRM by SalesAgility
CVE-2025-64492

8.8HIGH

Key Information:

Vendor

Suitecrm

Vendor
CVE Published:
8 November 2025

What is CVE-2025-64492?

SuiteCRM, an open-source CRM software, is affected by a time-based blind SQL Injection vulnerability in versions 8.9.0 and earlier. This flaw enables authenticated attackers to exploit the system by gauging database response times to infer sensitive information. Through this attack vector, they may enumerate database structures such as table and column names, extract confidential data, or even escalate their privileges within the system. The vulnerability has been addressed in version 8.9.1 of SuiteCRM.

Affected Version(s)

SuiteCRM-Core < 8.9.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64492 : Time-Based Blind SQL Injection in SuiteCRM by SalesAgility