CVE-2023-22952
sugarcrm
Published 11 Jan 2023 · updated 17 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 2 Feb 2023, with a remediation deadline of 23 Feb 2023 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
References
- packetstormsecurity.com/files/171320/SugarCRM-12.x-Remote-Code-Execution-Shell-Upload.html · Exploit, Third Party Advisory, VDB Entry
- support.sugarcrm.com/Resources/Security/sugarcrm-sa-2023-001/ · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22952 · US Government Resource