CVE-2025-25034 is a critical PHP object injection vulnerability affecting SugarCRM versions prior to 6.5.24, 6.7.13, 7.5.2.5, 7.6.2.2, and 7.7.1.0, stemming from inadequate sanitization of serialized input in the SugarRestSerialize.php script. This flaw allows an unauthenticated attacker to achieve arbitrary code execution by submitting specially crafted serialized data. With a CVSS score of 9.3 (CRITICAL) and an EPSS score indicating high exploitability, the vulnerability presents a severe risk due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-13 UTC, and public exploit modules are available in Metasploit and Nuclei, indicating active and widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.5.0, < 6.5.23CPE match | cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:*:*:*:* | ||
>= 6.7.0, < 6.7.12CPE match | cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:*:*:*:* | ||
>= 7.5.0, < 7.5.2.4CPE match | cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:*:*:*:* | ||
>= 7.6.0, < 7.6.2.1CPE match | cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.