CISA Known Exploited Vulnerability

CVE-2023-22952

SugarCRM · Multiple Products

Multiple SugarCRM Products Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-20
Ransomware Unknown

CISA description

Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates.

Required action

Apply updates per vendor instructions.