QID 730704

Date Published: 2023-01-20

QID 730704: SugarCRM Remote Code Execution (RCE) Vulnerability

SugarCRM is a customer relationship management system. SugarCRM's functionality includes sales-force automation, marketing campaigns, customer support, collaboration, Mobile CRM, Social CRM and reporting.

Affected Versions:
SugarCRM v11.0.0 prior to 11.0.5
SugarCRM v12.0.0 prior to 12.0.2

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version via sugar_version.json endpoint. Note: the detection os marked as practice since only some of the editions of SugarCRM are vulnerable.

Using a specially crafted request, custom PHP code can be injected through the EmailTemplates by the attacker.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to SugarCRM v11.0.5, v12.0.2 to remediate these vulnerabilities.
    Vendor References

    CVEs related to QID 730704

    Software Advisories
    Advisory ID Software Component Link
    sugarcrm-sa-2023-001 URL Logo support.sugarcrm.com/Resources/Security/sugarcrm-sa-2023-001/