Executive brief
Multiple SugarCRM products contain a remote code execution vulnerability due to missing input validation in the EmailTemplates module. An authenticated attacker can inject and execute custom PHP code via a specially crafted request.
Affected products
- SugarCRM SugarCRM before 12.0 Hotfix 91155; 11.0.0 to 11.0.5; 12.0.0 to 12.0.2
Timeline
- 2023-01-11: disclosed: NVD Published Date
- 2023-02-02: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2023-02-02: exploited: Reported as exploited in the wild