logo

Tracking a SugarCRM Zero-Day

ID: f610b5ae-800a-5d5a-afcf-6ebe9f5b938e

STIX ID: report--f610b5ae-800a-5d5a-afcf-6ebe9f5b938e

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2023-01-05

Date Updated: 2026-04-27

Author: Brenda Mendoza; Mark Ellzey; Senior Security Researcher

...
...

Censys reports on CVE-2023-22952, an authentication bypass in SugarCRM actively exploited in the wild to upload a PNG-encoded PHP webshell that executes base64-decoded commands; Censys observed hundreds of compromised hosts (reporting ~354 unique compromised IPs from ~3,059 Internet-facing SugarCRM instances), provides IOCs and detection commands (e.g., strings $INSTALLDIR/cache/images/* | grep -i PHP), and recommends applying SugarCRM hotfixes/updates and monitoring /cache/images/ HTTP requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.