SQL injection in SuiteCRM - CVE-2025-64488
Published: April 24, 2026
SuiteCRM
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information and compromise the database.
The vulnerability exists due to SQL injection in the Reschedule Call module when processing a crafted call_id parameter. A remote user can send a specially crafted call_id value to disclose sensitive information and compromise the database.