sw33t.0day

2 exploits Active since Jan 2023
CVE-2023-22952 METASPLOIT HIGH ruby WORKING POC
SugarCRM unauthenticated Remote Code Execution (RCE)
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
CVSS 8.8
EIP-2026-112471 EXPLOITDB python WORKING POC
SugarCRM 12.2.0 - Remote Code Execution (RCE)