Loading
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
Use CWE-20, Sugarcrm vendor hub and Sugarcrm product page to widen CVE-2023-22952 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-7472, CVE-2023-46816 and CVE-2023-46815 for nearby disclosures in the same product family.