PT-2023-17212 · Ibos · Ibos

Wkstestete

·

Publicado

2023-03-30

·

Atualizado

2024-05-17

·

CVE-2023-1747

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBOS versions up to 4.5.4
Description A critical vulnerability has been found in an unknown functionality of the file /?r=email/api/mark&op=delFromSend. The manipulation of the emailids argument leads to sql injection. The attack can be launched remotely. Upgrading to version 4.5.5 is able to address this issue.
Recommendations For IBOS versions up to 4.5.4, upgrade to version 4.5.5 to address the issue. As a temporary workaround, consider restricting access to the /?r=email/api/mark&op=delFromSend endpoint until the upgrade is applied. Avoid using the emailids argument in the affected endpoint until the issue is resolved.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-1747

Produtos afetados

Ibos