SuiteCRM SQL Injection Vulnerability in InboundEmail Module

Vulnerability

A SQL injection vulnerability has been identified in the InboundEmail module of SuiteCRM versions through 7.14.6. This vulnerability allows for the arbitrary execution of database queries, which could lead to unauthorized data access, modification, or deletion. The issue has been addressed in SuiteCRM version 7.14.7.

Impact

Exploitation of this vulnerability allows for authenticated blind SQL injection, with the potential to execute arbitrary SQL queries in the backend database. This could result in unauthorized data access, modification, or deletion, according to the CVE-2024-49773 reference.

Remediation

Users can upgrade to SuiteCRM version 7.14.7 to address this vulnerability.

Added: Aug 7, 2025, 12:17 AM
Updated: Aug 7, 2025, 12:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.2
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.