PT-2023-24195 · Xibo · Xibo

·

CVE-2023-33179

·

Publicado

2023-05-30

·

Atualizado

2023-06-06

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xibo versions 3.2.0 through 3.3.4
Description A SQL injection issue was discovered in the nameFilter function, allowing an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values for logical operators.
Recommendations For versions 3.2.0 through 3.3.4, upgrade to version 3.3.5 to resolve the issue. As a temporary workaround, consider restricting access to the nameFilter function until the upgrade to version 3.3.5 is completed.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-33179
GHSA-JMX8-CGM4-7MF5

Produtos afetados

Xibo