PT-2023-17212 · Ibos · Ibos

Wkstestete

·

Published

2023-03-30

·

Updated

2024-05-17

·

CVE-2023-1747

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBOS versions up to 4.5.4
Description A critical vulnerability has been found in an unknown functionality of the file /?r=email/api/mark&op=delFromSend. The manipulation of the emailids argument leads to sql injection. The attack can be launched remotely. Upgrading to version 4.5.5 is able to address this issue.
Recommendations For IBOS versions up to 4.5.4, upgrade to version 4.5.5 to address the issue. As a temporary workaround, consider restricting access to the /?r=email/api/mark&op=delFromSend endpoint until the upgrade is applied. Avoid using the emailids argument in the affected endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-1747

Affected Products

Ibos