---
id: CVE-2022-50589
title: "SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the\_processing of the ‘uid’ parameter within the ‘export’ functionality"
summary: "SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the\_processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute…"
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: salesagility
product: suitecrm
affected:
  - suitecrm < 7.12.6
patched:
  - suitecrm 7.12.6
published: '2025-11-06'
updated: '2026-07-15'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-50589'
references:
  - url: >-
      https://blog.exodusintel.com/2022/06/09/salesagility-suitecrm-export-request-sql-injection-vulnerability/
    label: disclosure@vulncheck.com
  - url: 'https://docs.suitecrm.com/admin/releases/7.12.x/#_7_12_6'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/suitecrm-sqli-via-export-functionality
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00643
epssPercentile: 0.48561
ingestedAt: '2026-07-15T13:44:03.405Z'
---

## Overview

SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code.

## Affected

- `suitecrm < 7.12.6`

## Remediation

Upgrade past the affected range:

- `suitecrm 7.12.6`
