HIGH

CVE-2023-22952

Sugarcrm Sugarcrm 2023-01-11 CVSS v3.1
CVSS
8.8
KEV

Description

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

Summary dbcve.org

A PHP code injection vulnerability in SugarCRM's EmailTemplates module allows remote attackers to inject and execute arbitrary PHP code through crafted requests due to insufficient input validation, providing unauthenticated RCE capability.

Mitigation

Apply Hotfix 91155 to SugarCRM 12.0 or upgrade to a patched version; restrict access to the EmailTemplates module to authorized users until the patch is applied.

Proof of Concept

Weakness (CWE)

CWE-20 Improper Input Validation
CWE-94 Code Injection

EPSS Score

80.14%
Probability of exploitation in next 30 days
99.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE