Lucene search

K
cvelistMitreCVELIST:CVE-2023-22952
HistoryJan 11, 2023 - 12:00 a.m.

CVE-2023-22952

2023-01-1100:00:00
mitre
www.cve.org
8
sugarcrm
emailtemplates
php injection
vulnerability
missing input validation

AI Score

8.9

Confidence

High

EPSS

0.534

Percentile

97.6%

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

AI Score

8.9

Confidence

High

EPSS

0.534

Percentile

97.6%