---
id: CVE-2022-50590
title: "SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the\_processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality"
summary: "SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the\_processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alte…"
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-843
vendor: salesagility
product: suitecrm
affected:
  - suitecrm < 7.12.6
patched:
  - suitecrm 7.12.6
published: '2025-11-06'
updated: '2026-07-15'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-50590'
references:
  - url: >-
      https://blog.exodusintel.com/2022/06/09/salesagility-suitecrm-deleteattachment-type-confusion-vulnerability/
    label: disclosure@vulncheck.com
  - url: 'https://docs.suitecrm.com/admin/releases/7.12.x/#_7_12_6'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/suitecrm-type-confusion-via-deleteattachment-functionality
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00363
epssPercentile: 0.27415
ingestedAt: '2026-07-15T13:44:03.425Z'
---

## Overview

SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within the processing of the ‘module’ parameter within the ‘deleteAttachment’ functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the administrator.

## Affected

- `suitecrm < 7.12.6`

## Remediation

Upgrade past the affected range:

- `suitecrm 7.12.6`
