CVE-2023-22952
SugarCRM Multiple Products
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
- CVSS
- 8.8
- EPSS
- 80.3% 99.6% percentile
- CISA KEV
- Listed
- Published
- 2023.01.11