Junglewise Threat Intelligence

CVE-2019-25663: SuiteCRM SQL injection in Emails module via parentTab parameter

CVE-2019-25663 · Severity: high · CVSS 7.1 · Published 2026-04-05

Technologies: Salesagility Suitecrm. Vendors: Salesagility.

Executive brief

SuiteCRM, a popular open-source customer relationship management platform, contains a security flaw in its email module. An authenticated user can exploit this vulnerability to run unauthorized database commands, potentially leading to the theft of sensitive customer data or business information. This could result in significant data breaches and loss of proprietary information stored within the CRM.

Technical details

A boolean-based SQL injection vulnerability exists in SuiteCRM version 7.10.7 within the 'Emails' module. The flaw is located in the handling of the 'parentTab' parameter during GET requests to index.php. An authenticated attacker can manipulate database queries by injecting malicious SQL code into this parameter, bypassing standard filters. This allows for the extraction of sensitive information from the underlying database. While the advisory focuses on version 7.10.7, users are encouraged to update to the latest stable maintenance releases (such as 7.14.x or 8.x) where these legacy issues are addressed.

Affected products

  • SalesAgility SuiteCRM 7.10.7

Timeline

  • 2019-02-04: disclosed: Original exploit published on Exploit-DB
  • 2026-04-05: advisory: CVE-2019-25663 published/updated via VulnCheck and NVD

References

Related threats