PT-2023-28353 · Sqlpage · Sqlpage
Lovasoa
·
Publicado
2023-09-18
·
Atualizado
2023-09-21
·
CVE-2023-42454
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SQLpage versions prior to 0.11.1
Description
SQLpage is a SQL-only webapp builder. An attacker can retrieve database connection information from SQLpage and use it to connect to the database directly if the SQLpage instance is exposed publicly, the database connection string is specified in the
sqlpage/sqlpage.json configuration file, the web root is the current working directory, and the database is exposed publicly.Recommendations
For SQLpage versions prior to 0.11.1, upgrade to version 0.11.1 as soon as possible.
As a temporary workaround, consider using an environment variable instead of the configuration file to specify the database connection string.
Using a different web root that is not a parent of the SQLPage configuration directory fixes the issue.
Avoid exposing the database publicly.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sqlpage