SQL injection in SuiteCRM - CVE-2026-61651
Published: August 1, 2026
SuiteCRM
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information and modify data.
The vulnerability exists due to SQL injection in the get_end_date action in Projects Controller when handling the task_id parameter. A remote user can send a specially crafted request to disclose sensitive information and modify data.
The issue may be exploited using blind SQL injection techniques to enumerate database schema and dump database contents.