CVE-2023-22952: Multiple SugarCRM Products Remote Code Execution Vulnerability
Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates. Required action: Apply updates per vendor instructions.
CISA KEV ↗ · unattributed attribution