CVE-2023-22952

sugarcrm

Published 11 Jan 2023 · updated 17 Jun 2026 · Analyzed

8.8 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 2 Feb 2023, with a remediation deadline of 23 Feb 2023 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

References