CVE-2023-22952: Multiple SugarCRM Products Remote Code Execution Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2023-02-02. EPSS: 80.1% chance of exploitation in the next 30 days.

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

Affected products

  • SugarCRM SugarCRM: from 11.0.0, before 11.0.5 (fixed in 11.0.5); from 12.0.0, before 12.0.2 (fixed in 12.0.2)

Published 2023-01-11. Last modified 2026-06-17.