Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 25 Nov 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Salesagility
Salesagility suitecrm |
|
| CPEs | cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Salesagility
Salesagility suitecrm |
Thu, 13 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Suitecrm
Suitecrm suitecrm |
|
| Vendors & Products |
Suitecrm
Suitecrm suitecrm |
Sat, 08 Nov 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 contain a privilege escalation vulnerability where user sessions are not invalidated upon account deactivation. An inactive user with an active session can continue to access the application and, critically, can self-reactivate their account. This undermines administrative controls and allows unauthorized persistence. This issue is fixed in versions 7.14.8 and 8.9.1. | |
| Title | SuiteCRM: Privilege Escalation via Improper Session Invalidation and Inactive User Bypass | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-13T21:36:24.585Z
Reserved: 2025-11-05T19:12:25.102Z
Link: CVE-2025-64489
Updated: 2025-11-13T21:36:21.988Z
Status : Analyzed
Published: 2025-11-08T01:15:38.607
Modified: 2025-11-25T17:31:42.657
Link: CVE-2025-64489
No data.
OpenCVE Enrichment
Updated: 2025-11-10T09:33:36Z