S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 18, 2025

CVE-2023-22952 Scanner

CVE-2023-22952 Scanner - Remote Code Execution vulnerability in SugarCRM

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-22952
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

SugarCRM is a customer relationship management software used by businesses to manage customer relationships and interactions. Organizations in various sectors like sales, marketing, and customer support implement SugarCRM for improving business operations. Its usage spans from small businesses to large enterprises aiming to optimize workflow and data handling. Many companies favor SugarCRM for its customization capabilities and ability to tailor to specific business needs. The solution aids in engaging customers, enhancing communication, and streamlining internal procedures. As a cloud-based or on-premise platform, it provides flexibility in data management and integration with other tools.

The vulnerability in question is a Remote Code Execution (RCE) flaw. This vulnerability allows attackers to execute arbitrary code on vulnerable systems. The SugarCRM platform, lacking sufficient input validation, is susceptible to this exploit. Malicious actors can craft inputs to inject and execute PHP code, achieving unauthorized actions. Detected in SugarCRM versions before 12.0. Hotfix 91155, this issue exposes systems to significant security risks. This vulnerability enables potential system access and control by unauthorized users if not patched timely.

The vulnerability exists due to missing input validation in the EmailTemplates module within SugarCRM. Exploits can inject malicious PHP code via crafted requests targeting this module. Attackers typically use the `/index.php` endpoint to leverage the code injection flaw. Vulnerable parameters include those associated with file uploads and user authentication actions. The pattern of attack involves posting filenames and actions that trick the system into executing unauthorized PHP scripts. Identifying the executed payload confirms a successful attack, indicating the presence of the vulnerability.

If exploited, this vulnerability can lead to severe consequences for affected systems. Exploiting it could allow attackers to gain unauthorized access to sensitive data or escalate privileges. It's possible to execute code that modifies, deletes, or exfiltrates important data. Additionally, attackers might install backdoors for persistent access or launch further attacks from compromised systems. Such vulnerabilities undermine trust in affected systems and may lead to data breaches, financial loss, or reputational damage. Ensuring systems are patched accordingly is crucial to prevent potential exploits.

REFERENCES

Solution Advice
  • Immediately update SugarCRM to the latest version that includes Hotfix 91155 or newer.
  • Ensure input validation is robust and specifically addresses the file upload functionality.
  • Consider implementing web application firewalls (WAF) to block suspicious requests.
  • Review and restrict permissions for accounts with access to vulnerable modules.
  • Conduct regular security audits to identify and mitigate potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.