PT-2023-20646 · Unknown · Imageconverter Service
Mdisec
·
Published
2023-11-02
·
Updated
2024-01-12
·
CVE-2023-26453
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
imageconverter service (affected versions not specified)
Description
The issue allows requests to cache an image to be abused, including SQL queries that would be executed unchecked. Exploiting this requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by default. Arbitrary SQL statements could be executed in the context of the service's database user account. API requests are now properly checked for valid content, and attempts to circumvent this check are being logged as an error. No publicly available exploits are known.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imageconverter Service