CVE-2023-22952 is a critical remote code execution (RCE) vulnerability affecting SugarCRM versions prior to 12.0 Hotfix 91155. It allows authenticated attackers to inject custom PHP code via crafted requests to EmailTemplates due to insufficient input validation. With a CVSS score of 8.8 (HIGH), this vulnerability is easily exploitable over the network with low complexity, enabling full compromise of confidentiality, integrity, and availability. This RCE is actively exploited in the wild, with public Metasploit modules and Nuclei templates available, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0.0, < 11.0.5CPE matchmatch criteria | cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:*:*:*:* | ||
>= 12.0.0, < 12.0.2CPE matchmatch criteria | cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.