CVE-2025-54785

Source
https://cve.org/CVERecord?id=CVE-2025-54785
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54785.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-54785
Aliases
  • GHSA-53cp-mpfw-qj67
Published
2025-08-06T23:15:16.718Z
Modified
2026-07-15T01:48:57.980751407Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
SuiteCRM is Vulnerable to PHP Object Injection in Reports
Details

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to penetration, privilege escalation, sensitive data exposure, Denial of Service, cryptomining and ransomware. This issue is fixed in version 7.14.7 and 8.8.1.

Database specific
{
    "cwe_ids": [
        "CWE-20"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54785.json",
    "cna_assigner": "GitHub_M",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "8.8.0"
                },
                {
                    "fixed": "8.8.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/suitecrm/suitecrm

Affected ranges

Type
GIT
Repo
https://github.com/suitecrm/suitecrm
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "7.14.6"
        },
        {
            "fixed": "7.14.7"
        }
    ]
}

Affected versions

v7.*
v7.14.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54785.json"