Impact
SuiteCRM versions 7.15.2 and 8.x through 8.10.2 expose a missing authorization flaw that lets an authenticated user create or modify EmailMarketing records via the setCampaignMarketingAndTemplate entry point. Users who do not normally have Campaigns access can post marketingId, campaignId, and templateId, which reattaches marketing messages or swaps the email template sent to campaign recipients. This flaw compromises the integrity of campaign content and allows malicious users to deliver altered or deceptive marketing emails.
Affected Systems
The vulnerability affects the SuiteCRM application. All installations running SuiteCRM 7.15.2 and those in the 8.x series up to and including 8.10.2 are impacted.
Risk and Exploitability
The CVSS score of 5.3 suggests a medium severity. Because the flaw is exploitable only by authenticated users and requires no special environmental conditions, the risk is manageable but non‑negligible. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. An attacker who possesses a user account—especially one with limited Campaigns permissions—can post to setCampaignMarketingAndTemplate and alter marketing templates, potentially compromising the integrity of campaign communications.
OpenCVE Enrichment