Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 25 Nov 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Salesagility
Salesagility suitecrm |
|
| CPEs | cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Salesagility
Salesagility suitecrm |
Thu, 13 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Suitecrm
Suitecrm suitecrm |
|
| Vendors & Products |
Suitecrm
Suitecrm suitecrm |
Sat, 08 Nov 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 through 8.9.0 allow a low-privileged user with a restrictive role to view and create work items through the Resource Calendar and project screens, even when the related modules (Projects, Project Tasks, Tasks, Leads, Accounts, Meetings, Calls) are explicitly set to Disabled/None in Role Management. This indicates inconsistent ACL/RBAC enforcement across modules and views, resulting in unauthorized data exposure and modification. This issue is fixed in versions 7.14.8 and 8.9.1. | |
| Title | SuiteCRM's Inconsistent RBAC Enforcement Enables Access Control Bypass | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-13T21:37:07.901Z
Reserved: 2025-11-05T19:12:25.102Z
Link: CVE-2025-64490
Updated: 2025-11-13T21:37:02.249Z
Status : Analyzed
Published: 2025-11-08T01:15:38.830
Modified: 2025-11-25T17:32:46.020
Link: CVE-2025-64490
No data.
OpenCVE Enrichment
Updated: 2025-11-10T09:33:37Z