Junglewise Threat Intelligence

CVE-2023-22952: Multiple SugarCRM Products Remote Code Execution Vulnerability

CVE-2023-22952 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-02-02

Technologies: Apple Multiple Products. Vendors: Apple.

Executive brief

Multiple SugarCRM products contain a remote code execution vulnerability due to missing input validation in the EmailTemplates module. An authenticated attacker can inject and execute custom PHP code via a specially crafted request.

Affected products

  • SugarCRM SugarCRM before 12.0 Hotfix 91155; 11.0.0 to 11.0.5; 12.0.0 to 12.0.2

Timeline

  • 2023-01-11: disclosed: NVD Published Date
  • 2023-02-02: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-02-02: exploited: Reported as exploited in the wild

Related threats