---
id: CVE-2019-25664
title: >-
  SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the
  record parameter of the Users module DetailView action that allows
  authenticated attackers to manipulate database queries
summary: >-
  SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the
  record parameter of the Users module DetailView action that allows
  authenticated attackers to manipulate database queries. Attackers can append
  SQL code to the reco…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-89
vendor: salesagility
product: suitecrm
affected:
  - suitecrm <= 7.10.7
published: '2026-04-05'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-25664'
references:
  - url: 'https://suitecrm.com/'
    label: disclosure@vulncheck.com
  - url: 'https://suitecrm.com/download/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/46311'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/suitecrm-sql-injection-via-record-parameter
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00342
epssPercentile: 0.2557
ingestedAt: '2026-10-06T22:23:15.917Z'
---

## Overview

SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to manipulate database queries. Attackers can append SQL code to the record parameter in GET requests to the index.php endpoint to extract sensitive database information through time-based blind SQL injection techniques.

## Affected

- `suitecrm <= 7.10.7`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
