CVE-2023-22952

CVE Published 2023-01-11
Related CWE(s) CWE-20: Improper Input Validation
Related Vendor(s) sugarcrm
Related Product(s) sugarcrm
Exploitation Reported (CISA KEV) 2023-02-02
CVSS 3 Base Score 8.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References