Beveiligingsadvies

CVE-2023-22952

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-01-11 00:00:00
Laatst bijgewerkt 2025-10-21 23:15:28
Toegewezen door mitre
CVSS-score 8.8
Status PUBLISHED

Beschrijving

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.