SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the email module with malicious parentTab values using boolean-based SQL injection techniques to extract sensitive database information.
References
| Link | Resource |
|---|---|
| https://suitecrm.com/ | Product |
| https://suitecrm.com/download/ | Product |
| https://www.exploit-db.com/exploits/46310 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/suitecrm-sql-injection-via-parenttab-parameter | Third Party Advisory |
Configurations
History
20 Apr 2026, 18:11
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://suitecrm.com/ - Product | |
| References | () https://suitecrm.com/download/ - Product | |
| References | () https://www.exploit-db.com/exploits/46310 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/suitecrm-sql-injection-via-parenttab-parameter - Third Party Advisory | |
| CPE | cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:* | |
| First Time |
Salesagility
Salesagility suitecrm |
05 Apr 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-05 21:16
Updated : 2026-06-17 02:32
NVD link : CVE-2019-25663
Mitre link : CVE-2019-25663
CVE.ORG link : CVE-2019-25663
JSON object : View
Products Affected
salesagility
- suitecrm
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
