PT-2023-20647 · Unknown · Imageconverter Service
Mdisec
+1
·
Publicado
2023-11-02
·
Atualizado
2024-01-12
·
CVE-2023-26454
CVSS v3.1
8.8
Alta
| Vetor | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
imageconverter service (affected versions not specified)
Description
The issue allows requests to fetch image metadata to be abused, including SQL queries that would be executed unchecked. This requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by default. Arbitrary SQL statements could be executed in the context of the service's database user account. API requests are now properly checked for valid content, and attempts to circumvent this check are being logged as an error.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Imageconverter Service