CVE-2023-46816: SugarCRM

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified in the GecControl action. By using a crafted request, custom PHP code can be injected via the GetControl action because of missing input validation. An attacker with regular user privileges can exploit this.

Affected products

  • SugarCRM SugarCRM: from 12.0.0, before 12.0.4 (fixed in 12.0.4); version 13.0.0 only; version 13.0.1 only

Published 2023-10-27. Last modified 2026-06-17.