Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 20 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:salesagility:suitecrm:*:*:*:*:*:*:*:* |
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Suitecrm
Suitecrm suitecrm |
|
| Vendors & Products |
Suitecrm
Suitecrm suitecrm |
Mon, 06 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 05 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the email module with malicious parentTab values using boolean-based SQL injection techniques to extract sensitive database information. | |
| Title | SuiteCRM 7.10.7 SQL Injection via parentTab Parameter | |
| First Time appeared |
Salesagility
Salesagility suitecrm |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:salesagility:suitecrm:7.10.7:*:*:*:*:*:*:* | |
| Vendors & Products |
Salesagility
Salesagility suitecrm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-06T15:27:46.638Z
Reserved: 2026-04-05T13:01:18.962Z
Link: CVE-2019-25663
Updated: 2026-04-06T15:08:18.265Z
Status : Analyzed
Published: 2026-04-05T21:16:43.393
Modified: 2026-04-20T18:11:50.063
Link: CVE-2019-25663
No data.
OpenCVE Enrichment
Updated: 2026-04-06T21:56:14Z