---
id: CVE-2019-25663
title: >-
  SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows
  authenticated attackers to manipulate database queries by injecting SQL code
  through the parentTab parameter
summary: >-
  SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows
  authenticated attackers to manipulate database queries by injecting SQL code
  through the parentTab parameter. Attackers can send GET requests to the email
  module with mal…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-89
vendor: salesagility
product: suitecrm
affected:
  - suitecrm <= 7.10.7
published: '2026-04-05'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-25663'
references:
  - url: 'https://suitecrm.com/'
    label: disclosure@vulncheck.com
  - url: 'https://suitecrm.com/download/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/46310'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/suitecrm-sql-injection-via-parenttab-parameter
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00342
epssPercentile: 0.2557
ingestedAt: '2026-10-06T22:23:15.917Z'
---

## Overview

SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the email module with malicious parentTab values using boolean-based SQL injection techniques to extract sensitive database information.

## Affected

- `suitecrm <= 7.10.7`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
