SuiteCRM versions through 7.12.1 and 8.x through 8.0.1 are vulnerable to remote code execution due to unsafe PHP deserialization in the Scheduled Reports module. Authenticated users can inject a crafted PHP object payload into the email_recipients property of a report. When the report is accessed, the backend deserializes this property, allowing execution of arbitrary code. The vulnerability is exacerbated by the presence of exploitable deserialization gadgets in project dependencies, such as Monolog/RCE1 from phpggc.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a working proof-of-concept exploit for CVE-2022-23940, a critical authenticated remote code execution vulnerability in SuiteCRM (<= 7.12.4) and SuiteCRM-Core (<= 8.0.3). The exploit leverages a PHP deserialization flaw in the AOR_Scheduled_Reports module, where the 'email_recipients' field is unsafely deserialized from user input. The main exploit script, 'exploit.py', is a Python3 tool that authenticates to a target SuiteCRM instance using provided credentials, crafts a malicious serialized PHP object (using the Monolog/RCE2 gadget chain), and injects it into a scheduled report via an HTTP POST request. The payload is customizable and can execute arbitrary shell commands, such as spawning a reverse shell. The exploit then triggers the scheduled report to achieve code execution. The repository also includes a Docker Compose setup for a vulnerable SuiteCRM instance for testing. The exploit is operational and demonstrates real-world impact, but is not part of a larger exploitation framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.