CVE-2019-25663

SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the email module with malicious parentTab values using boolean-based SQL injection techniques to extract sensitive database information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*

History

20 Apr 2026, 18:11

Type Values Removed Values Added
References () https://suitecrm.com/ - () https://suitecrm.com/ - Product
References () https://suitecrm.com/download/ - () https://suitecrm.com/download/ - Product
References () https://www.exploit-db.com/exploits/46310 - () https://www.exploit-db.com/exploits/46310 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/suitecrm-sql-injection-via-parenttab-parameter - () https://www.vulncheck.com/advisories/suitecrm-sql-injection-via-parenttab-parameter - Third Party Advisory
CPE cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:*
First Time Salesagility
Salesagility suitecrm

05 Apr 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-05 21:16

Updated : 2026-06-17 02:32


NVD link : CVE-2019-25663

Mitre link : CVE-2019-25663

CVE.ORG link : CVE-2019-25663


JSON object : View

Products Affected

salesagility

  • suitecrm
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')