SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the administrator.
History

Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Suitecrm
Suitecrm suitecrm
Vendors & Products Suitecrm
Suitecrm suitecrm

Fri, 07 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
Description SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the administrator.
Title SuiteCRM < 7.12.6 Type Confusion via 'deleteAttachment' Functionality
Weaknesses CWE-843
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-11-06T19:59:36.078Z

Updated: 2025-11-06T20:26:09.006Z

Reserved: 2025-11-05T14:54:49.234Z

Link: CVE-2022-50590

cve-icon Vulnrichment

Updated: 2025-11-06T20:26:01.443Z

cve-icon NVD

Status : Received

Published: 2025-11-06T20:15:36.990

Modified: 2025-11-06T20:15:36.990

Link: CVE-2022-50590

cve-icon Redhat

No data.