Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 25 Nov 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Salesagility
Salesagility suitecrm |
|
| CPEs | cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Salesagility
Salesagility suitecrm |
Mon, 10 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Nov 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Suitecrm
Suitecrm suitecrm |
|
| Vendors & Products |
Suitecrm
Suitecrm suitecrm |
Sat, 08 Nov 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8.6.0 through 8.9.0, there is an authenticated, blind (time-based) SQL-injection inside the appMetadata-operation of the GraphQL-API. This allows extraction of arbitrary data from the database, and does not require administrative access. This issue is fixed in version 8.9.1. | |
| Title | SuiteCRM is Vulnerable to Authenticated Blind SQL Injection via GraphQL | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-10T16:39:27.970Z
Reserved: 2025-11-05T19:12:25.103Z
Link: CVE-2025-64493
Updated: 2025-11-10T16:39:20.223Z
Status : Analyzed
Published: 2025-11-08T02:15:34.880
Modified: 2025-11-25T17:33:58.810
Link: CVE-2025-64493
No data.
OpenCVE Enrichment
Updated: 2025-11-10T09:33:28Z