Security hole in SugarCRM servers actively exploited
Summary
In early 2023 attackers exploited a critical hole in SugarCRM (CVE-2023-22952) to take over servers and install malware. Authentication could be bypassed via the path /index.php/, after which a POST request uploaded a PNG file containing PHP code that was executed when called up later. By 11 January Censys found 354 compromised servers, just under twelve percent of all 3,059 reachable instances.
Ideas
- Exploit code was circulating publicly even before the hotfix.
- An image file with embedded PHP code served as a backdoor.
- Only installations with the Sugaridentity identity management were not affected.
- Cloud instances operated by SugarCRM were patched immediately.
Insights
- Self-hosted business software is only as secure as its operators’ patching speed.
- After a patch, you also have to check whether a break-in has already happened.
Facts
- SugarCRM published an advisory and hotfix on 5 January 2023.
- Most compromised servers were in the USA, Germany, Australia and France.
References
Critique
- The report refers to Censys’ indicators of compromise but does not list them itself.
Recommendations
- After critical holes, check your own servers against published indicators of compromise.
- In web applications, prevent scripts from being executed in upload and cache directories.
Links to the original source and the Web Archive open in a new tab.