CVE-2022-50590

MEDIUM

SuiteCRM <7.12.6 - Code Injection

Title source: llm
STIX 2.1

Description

SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the administrator.

Scores

CVSS v3 5.3
EPSS 0.0004
EPSS Percentile 11.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-843
Status published
Products (1)
salesagility/suitecrm < 7.12.6
Published Nov 06, 2025
Tracked Since Feb 18, 2026