CVE-2023-22952
HIGH KEV NUCLEISugarCRM unauthenticated Remote Code Execution (RCE)
Title source: metasploitExploitation Summary
CVE-2023-22952 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added February 2, 2023.
EIP tracks 1 public exploit from researchers including Sw33t.0day, including a Metasploit module exploits/multi/http/sugarcrm_webshell_cve_2023_22952.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits CVE-2023-22952, an unauthenticated RCE vulnerability in SugarCRM. It uploads a malicious PNG file with embedded PHP code to the server via a vulnerable endpoint, then executes arbitrary commands through the uploaded webshell.
Description
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
Exploits (1)
This Metasploit module exploits CVE-2023-22952, an unauthenticated RCE vulnerability in SugarCRM. It uploads a malicious PNG file with embedded PHP code to the server via a vulnerable endpoint, then executes arbitrary commands through the uploaded webshell.
Nuclei Templates (1)
http.html:"sugarcrm inc. all rights reserved" || http.title:"sugar setup wizard" || http.title:"sugarcrm"
body="sugarcrm inc. all rights reserved" || title="sugar setup wizard" || title=sugarcrm
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H