SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the administrator.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 06 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the administrator. | |
| Title | SuiteCRM < 7.12.6 Type Confusion via 'deleteAttachment' Functionality | |
| Weaknesses | CWE-843 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-06T20:26:09.006Z
Reserved: 2025-11-05T14:54:49.234Z
Link: CVE-2022-50590
No data.
Status : Received
Published: 2025-11-06T20:15:36.990
Modified: 2025-11-06T20:15:36.990
Link: CVE-2022-50590
No data.
OpenCVE Enrichment
No data.