CVE-2023-22952

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
11/01/2023
Last modified:
03/11/2025

Description

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:*:*:*:* 11.0.0 (including) 11.0.5 (excluding)
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:*:*:*:* 12.0.0 (including) 12.0.2 (excluding)