CVE-2023-22952

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

  • Published Jan 11, 2023
  • CVSS 8.8 high
  • 80.1% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • A Metasploit module exploits it
  • A fix is available

CVE-2023-22952 at the National Vulnerability Database