In SugarCRM before 12.0. Hotfix 91155, a crafted request...
High severity
Unreviewed
Published
Jan 11, 2023
to the GitHub Advisory Database
•
Updated Jan 29, 2025
Description
Published by the National Vulnerability Database
Jan 11, 2023
Published to the GitHub Advisory Database
Jan 11, 2023
Last updated
Jan 29, 2025
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
References