CVE-2025-64492 HIGH

CVE-2025-64492: SuiteCRM is Vulnerable to Authenticated Time Based Blind SQL Injection

Vendor Suitecrm
Product SuiteCRM-Core
Weakness CWE-89 · SQLi
Published November 8, 2025
Last update November 10, 2025

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0 and below contain a time-based blind SQL Injection vulnerability. This vulnerability allows an authenticated attacker to infer data from the database by measuring response times, potentially leading to the extraction of sensitive information. It is possible for an attacker to enumerate database, table, and column names, extract sensitive data, or escalate privileges. This is fixed in version 8.9.1.

Key dates

02Disclosure timeline

November 8, 2025 CVE published
November 10, 2025 Record updated