CVE-2022-50590
06.11.2025, 20:15
SuiteCRM versions prior to 7.12.6 contain a type confusion vulnerability within theprocessing of the module parameter within the deleteAttachment functionality. Successful exploitation allows remote unauthenticated attackers to alter database objects including changing the email address of the administrator.
Awaiting analysis
This vulnerability is currently awaiting analysis.