CVE-2009-2146

SugarCRM < 5.2f - Authenticated Remote Code Execution via Compose Email File Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2146. PoCs published by USH.

AI-analyzed exploit summary This advisory details a remote code execution vulnerability in SugarCRM 5.2.0e, where a flawed file extension validation routine allows attackers to upload malicious PHP files by exploiting a logic error in the `safeAttachmentName` function. The writeup provides a step-by-step explanation of the vulnerability, its exploitation, and mitigation.

Description

Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name.

Exploits (1)

exploitdb WRITEUP VERIFIED
by USH · textwebappsphp
https://www.exploit-db.com/exploits/8949

This advisory details a remote code execution vulnerability in SugarCRM 5.2.0e, where a flawed file extension validation routine allows attackers to upload malicious PHP files by exploiting a logic error in the `safeAttachmentName` function. The writeup provides a step-by-step explanation of the vulnerability, its exploitation, and mitigation.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SugarCRM 5.2.0e and possibly earlier versions
Auth required
Prerequisites: Valid user account on the SugarCRM instance · File upload functionality enabled in the 'Compose Email' section
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35445
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35361

Scores

EPSS 0.2147
EPSS Percentile 97.3%

Details

Status published
Products (9)
sugarcrm/sugarcrm 5.0.0
sugarcrm/sugarcrm 5.0.0h
sugarcrm/sugarcrm 5.0.0k
sugarcrm/sugarcrm 5.1.0
sugarcrm/sugarcrm 5.1.0-beta
sugarcrm/sugarcrm 5.1c
sugarcrm/sugarcrm 5.2c
sugarcrm/sugarcrm 5.2d
sugarcrm/sugarcrm < 5.2e
Published Jun 22, 2009
Tracked Since Feb 18, 2026