Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-22952 PoC — SugarCRM 输入验证错误漏洞

Source
Associated Vulnerability
Title:SugarCRM 输入验证错误漏洞 (CVE-2023-22952)
Description:SugarCRM是美国SugarCRM公司的一套开源的客户关系管理系统(CRM)。该系统支持对不同的客户需求进行差异化营销、管理和分配销售线索,实现销售代表的信息共享和追踪。 SugarCRM 12.0之前版本存在安全漏洞,该漏洞源于缺少输入验证,精心设计的请求可以通过电子邮件模板注入自定义 PHP 代码。
Description
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
File Snapshot

id: CVE-2023-22952 info: name: SugarCRM Unauthenticated - Remote Code Execution author: iamnooo ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.