CVE-2025-64493 MEDIUM

CVE-2025-64493: SuiteCRM is Vulnerable to Authenticated Blind SQL Injection via GraphQL

Vendor Suitecrm
Product SuiteCRM-Core
Weakness CWE-89 · SQLi
Published November 8, 2025
Last update November 10, 2025

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8.6.0 through 8.9.0, there is an authenticated, blind (time-based) SQL-injection inside the appMetadata-operation of the GraphQL-API. This allows extraction of arbitrary data from the database, and does not require administrative access. This issue is fixed in version 8.9.1.

Key dates

02Disclosure timeline

November 8, 2025 CVE published
November 10, 2025 Record updated