CVE-2022-50590

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
06/11/2025
Last modified:
24/11/2025

Description

SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the administrator.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:* 7.12.6 (excluding)