Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-25034— SugarCRM PHP Deserialization RCE

Quick assessment

Affected
SugarCRM SugarCRM
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SugarCRM是美国SugarCRM公司的一套开源的客户关系管理系统(CRM)。该系统支持对不同的客户需求进行差异化营销、管理和分配销售线索,实现销售代表的信息共享和追踪。 SugarCRM存在安全漏洞,该漏洞源于对SugarRestSerialize.php中rest_data参数的反序列化验证不足,可能导致任意代码执行。以下版本受到影响:6.5.24之前版本、6.7.13之前版本、7.5.2.5之前版本、7.6.2.2之前版本和7.7.1.0之前版本。

AI Predicted 9.8 Difficulty: Easy EPSS 4.96% · P92

Affected Version Matrix 4

VendorProduct Version RangeStatus
SugarCRM SugarCRM 6.5.0< 6.5.23 affected
6.7.0< 6.7.12 affected
7.5.0< 7.5.2.4 affected
7.6.0< 7.6.2.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-25034

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SugarCRM PHP Deserialization RCE
Source: CVE Program / CVE List V5
Vulnerability Description
A PHP object injection vulnerability exists in SugarCRM versions prior to 6.5.24, 6.7.13, 7.5.2.5, 7.6.2.2, and 7.7.1.0 due to improper validation of PHP serialized input in the SugarRestSerialize.php script. The vulnerable code fails to sanitize the rest_data parameter before passing it to the unserialize() function. This allows an unauthenticated attacker to submit crafted serialized data containing malicious object declarations, resulting in arbitrary code execution within the application context. Although SugarCRM released a prior fix in advisory sugarcrm-sa-2016-001, the patch was incomplete and failed to address some vectors. Exploitation evidence was observed by the Shadowserver Foundation on 2024-09-13 UTC.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5
Vulnerability Title
SugarCRM 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SugarCRM是美国SugarCRM公司的一套开源的客户关系管理系统(CRM)。该系统支持对不同的客户需求进行差异化营销、管理和分配销售线索,实现销售代表的信息共享和追踪。 SugarCRM存在安全漏洞,该漏洞源于对SugarRestSerialize.php中rest_data参数的反序列化验证不足,可能导致任意代码执行。以下版本受到影响:6.5.24之前版本、6.7.13之前版本、7.5.2.5之前版本、7.6.2.2之前版本和7.7.1.0之前版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
SugarCRM SugarCRM 6.5.0 ~ 6.5.23 -

II. Public POCs for CVE-2025-25034

# POC Description Source Link Shenlong Link
1 A PHP object injection vulnerability exists in SugarCRM versions prior to 6.5.24, 6.7.13, 7.5.2.5, 7.6.2.2, and 7.7.1.0 due to improper validation of PHP serialized input in the SugarRestSerialize.php script. The vulnerable code fails to sanitize the rest_data parameter before passing it to the unserialize() function. This allows an unauthenticated attacker to submit crafted serialized data containing malicious object declarations, resulting in arbitrary code execution within the application context. Although SugarCRM released a prior fix in advisory sugarcrm-sa-2016-001, the patch was incomplete and failed to address some vectors. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-25034.yaml POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-25034

请登录查看更多情报信息。

Vendor Advisories for CVE-2025-25034 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2025-25034

No comments yet


Leave a comment