SQL injection in SuiteCRM - CVE-2026-61653
Published: August 1, 2026
SuiteCRM
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in modules/Campaigns/PopupCampaignRoi.php when handling the $_REQUEST['id'] parameter. A remote user can send a specially crafted request to disclose sensitive information.
The issue can be exploited through time-based blind SQL injection, and access to the Campaigns module is required.