Unrated severityNVD Advisory· Published Nov 6, 2025· Updated Nov 28, 2025
SuiteCRM < 7.12.6 SQL Injection via 'export' Functionality
CVE-2022-50589
Description
SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <7.12.6
Patches
Vulnerability mechanics
References
3- docs.suitecrm.com/admin/releases/7.12.x/mitrevendor-advisorypatch
- www.vulncheck.com/advisories/suitecrm-sqli-via-export-functionalitymitrethird-party-advisory
- blog.exodusintel.com/2022/06/09/salesagility-suitecrm-export-request-sql-injection-vulnerability/mitretechnical-description
News mentions
0No linked articles in our index yet.