CVE-2023-22952
π₯ Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
Vulnerability Description
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
Affected Platforms (CPE)
π¦
Sugarcrm
Sugarcrm
>= 11.0.0 and < 11.0.5>= 12.0.0 and < 12.0.2
