HIGH
CVE-2023-22952
CVSS
8.8
KEV
Description
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
Summary dbcve.org
A PHP code injection vulnerability in SugarCRM's EmailTemplates module allows remote attackers to inject and execute arbitrary PHP code through crafted requests due to insufficient input validation, providing unauthenticated RCE capability.
Mitigation
Apply Hotfix 91155 to SugarCRM 12.0 or upgrade to a patched version; restrict access to the EmailTemplates module to authorized users until the patch is applied.
Weakness (CWE)
CWE-20
Improper Input Validation
CWE-94
Code Injection
EPSS Score
80.14%
Probability of exploitation in next 30 days
99.6th percentile
References
http://packetstormsecurity.com/files/171320/SugarCRM-12.x-Remote-Code-Execution-Shell-Upload.html
Exploit, Third Party Advisory, VDB Entry
https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2023-001/
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22952
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.