CVE-2025-64493

MEDIUM

SuiteCRM 8.6.0-8.9.0 - Authenticated Blind SQL Injection via GraphQL API appMetadata Operation

Title source: llm
STIX 2.1

Description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8.6.0 through 8.9.0, there is an authenticated, blind (time-based) SQL-injection inside the appMetadata-operation of the GraphQL-API. This allows extraction of arbitrary data from the database, and does not require administrative access. This issue is fixed in version 8.9.1.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0029
EPSS Percentile 20.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
salesagility/suitecrm 8.6.0 - 8.9.1
Published Nov 08, 2025
Tracked Since Feb 18, 2026