claytonvantol.us
SESSION: secure TLS: 1.3 PID: 1337

clayton@site:~/news$ cat cve-2023-22952-sugarcrm-multiple-products.log

CVE-2023-22952 — Multiple SugarCRM Products Remote Code Execution Vulnerability

2023-02-02 • CISA Known Exploited Vulnerability


[event] Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates.

> AFFECTED SOFTWARE

Field Value
Vendor SugarCRM
Product Multiple Products
CWE CWE-20
CVE ID CVE-2023-22952
Date Added 2023-02-02
Due Date 2023-02-23
Ransomware Campaign Unknown

> MITIGATION

Apply updates per vendor instructions.

Due Date: 2023-02-23

> REFERENCES


← back to terminal

UPTIME: 1337d v2.0.1 privacy LAST LOGIN: 2026-05-30 20:36:11 UTC