Vulnerabilities
48 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-46816 +1 in the same advisory: …46815 | An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified in the GecControl action. By using a crafted request, custom PHP code can be injected via the GetControl action because of missing input validation. An attacker with regular user privileges can exploit this. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2023-35809 | An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Bean Manipulation vulnerability has been identified in the REST API. By using a crafted request, custom PHP code can be injected through the REST API because of missing input validation. Regular user privileges can be used to exploit this vulnerability. Editions other than Enterprise are also affected. NVD description · AI analysis pending | 8.8 group max | 1% |
| — | ||
| CVE-2023-22952 | Authenticated PHP Code Injection RCE in SugarCRM EmailTemplates CVE-2023-22952 is a remote code execution vulnerability in multiple SugarCRM products caused by missing input validation (CWE-20) that permits PHP code injection (CWE-94) through the EmailTemplates feature. An attacker with low-privilege (authenticated) access sends a crafted request to EmailTemplates that injects and executes arbitrary custom PHP code on the server. Successful exploitation yields full server-side code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8), and the associated public proof-of-concept demonstrates shell upload, creating risk of follow-on activity such as ransomware. Organizations running affected SugarCRM releases prior to 12.0 Hotfix 91155 are exposed. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2023-02-02, EPSS assigns an 80.1% probability of exploitation within 30 days (100th percentile), and trade press reported active attacks. Do: Apply the vendor fix immediately per CISA's KEV required action — SugarCRM 12.0 Hotfix 91155 or a later patched release per vendor instructions. Audit EmailTemplates and the server filesystem for injected PHP code or uploaded webshells, and review web logs for crafted requests to EmailTemplates endpoints. Treat unpatched, internet-exposed SugarCRM instances as high priority, as ransomware use is listed as unknown and active exploitation is confirmed. | 8.8 | 80% | KEV PoC |
| moderate≈10k–100k users across thousands of independently deployed business instances (order-of-magnitude estimate) | |
| CVE-2020-36501 | Multiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML via craf Multiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the primary address state or alternate address state input fields. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2020-7472 | An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 1 An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code execution against a configured SugarCRM instance via crafted HTTP requests. (This is exploitable even after installation is completed.). NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2020-17372 +1 in the same advisory: …17373 | SugarCRM before 10.1.0 (Q3 2020) allows XSS. SugarCRM before 10.1.0 (Q3 2020) allows XSS. NVD description · AI analysis pending | 5.4 group max | <1% | PoC ×2 |
| — | |
| CVE-2019-17313 | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Studio module by a Developer user. SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Studio module by a Developer user. NVD description · AI analysis pending | 8.8 group max | 2% |
| — | ||
| CVE-2019-14974 | SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS. SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS. NVD description · AI analysis pending | 6.1 | 28% | PoC |
| — | |
| CVE-2018-17784 | Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system. NVD description · AI analysis pending | 6.1 | 4% | PoC |
| — | |
| CVE-2018-6308 | Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaigns\Tracker.php and modules\Campaigns\util Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaigns\Tracker.php and modules\Campaigns\utils.php, the default_currency_name parameter to modules\Configurator\controller.php and modules\Currencies\Currency.php, the duplicate parameter to modules\Contacts\ShowDuplicates.php, the mergecur parameter to modules\Currencies\index.php and modules\Opportunities\Opportunity.php, and the load_signed_id parameter to modules\Documents\Document.php. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2018-5715 | phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable). phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable). NVD description · AI analysis pending | 6.1 | 7% | PoC ×2 |
| — | |
| CVE-2017-14509 | An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). A remote file inclusion has been identified in the Connectors module allowing authenticated users to include remotely accessible system files via a module=CallRest&url= query string. Proper input validation has been added to mitigate this issue. NVD description · AI analysis pending | 8.8 group max | 6% | PoC |
| — |