


Perceptive Security
SOC/SIEM Consultancy

SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the pareā¦
Published:
4 april 2026 om 22:00:00
Alert date:
5 april 2026 om 22:09:03
Source:
nvd.nist.gov
Web Technologies, Database & Storage
SuiteCRM version 7.10.7 contains a SQL injection vulnerability affecting authenticated users. The vulnerability exists in the parentTab parameter of the email module, allowing attackers to manipulate database queries through GET requests. Attackers can exploit this using boolean-based SQL injection techniques to extract sensitive database information. The vulnerability requires authentication but allows for database manipulation and information disclosure. Multiple advisories and exploit code are available publicly for this CVE.
Technical details
Mitigation steps:
Affected products:
SuiteCRM
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2019-25663
https://suitecrm.com/
https://suitecrm.com/download/
https://www.exploit-db.com/exploits/46310
https://www.vulncheck.com/advisories/suitecrm-sql-injection-via-parenttab-parameter
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
