CVE-2019-25664Disclosure(salesagility / suitecrm)

LOWCVSS 7.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to manipulate database queries. Attackers can append SQL code to the record parameter in GET requests to the index.php endpoint to extract sensitive database information through time-based blind SQL injection techniques.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • suitecrm

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
suitecrm

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-05: 2Technical Details · 2026-04-05: 204-05
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2019-25664 SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to… https://www.cve.org/CVERecord?id=CVE-2019-25664 ----- Traducción: CVE-2019-25664 Sui… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2019-25664, describing a time‑based SQL injection vulnerability in SuiteCRM 7.10.7, with no mention of proof‑of‑concept, exploit code, active exploitation, or patches.

    0000025
    63 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2019-25664 SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to… https://www.cve.org/CVERecord?id=CVE-2019-25664

    Post summary

    The post discloses that CVE-2019-25664 is a time‑based SQL injection vulnerability in SuiteCRM 7.10.7, but does not provide PoC, exploit code, or patch details.

    00000190
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsalesagilitysuitecrm---

Explore more