First published: Wed Jan 11 2023(Updated: )
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sugarcrm Sugarcrm | >=11.0.0<11.0.5 | |
Sugarcrm Sugarcrm | >=12.0.0<12.0.2 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22952 is a remote code execution vulnerability found in multiple SugarCRM products.
CVE-2023-22952 allows a malicious actor to inject custom PHP code through the EmailTemplates functionality in SugarCRM products.
The severity of CVE-2023-22952 is high.
To mitigate CVE-2023-22952, it is recommended to apply the security patch provided by SugarCRM.
You can find more information about CVE-2023-22952 in the SugarCRM support website: https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2023-001/