CVE-2022-50589

Severity CVSS v4.0:
CRITICAL
Type:
CWE-89 SQL Injection
Publication date:
06/11/2025
Last modified:
24/11/2025

Description

SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:* 7.12.6 (excluding)