Executive brief
SuiteCRM, a popular open-source customer relationship management platform, is vulnerable to a critical security flaw in its data export feature. An attacker can exploit this to gain unauthorized access to the underlying database and potentially take full control of the server. This could lead to the theft of sensitive customer data, service disruption, or the installation of malicious software.
Technical details
A SQL injection vulnerability exists in SuiteCRM versions prior to 7.12.6 due to improper neutralization of the 'uid' parameter within the 'export' functionality. An unauthenticated remote attacker can exploit this by sending a specially crafted network request to the vulnerable endpoint. Successful exploitation allows the attacker to execute arbitrary SQL commands, which can be leveraged to achieve remote code execution (RCE) on the underlying host. The vulnerability was patched in version 7.12.6.
Affected products
- SalesAgility SuiteCRM < 7.12.6
Timeline
- 2022-03-02: disclosed: Disclosed to vendor by Exodus Intelligence
- 2022-06-09: advisory: Public disclosure by Exodus Intelligence
- 2025-11-06: advisory: NVD publication