Fiche vulnérabilité
CVE-2022-50590 : faille moyenne salesagility suitecrm (CVSS 5.3)
Description
SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the administrator.
En bref
- Sévérité
- Moyenne (CVSS 5.3)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 6 nov. 2025
- Dernière mise à jour
- 15 juil. 2026
Produits concernés
- salesagility suitecrm