PT-2023-20647 · Unknown · Imageconverter Service
Mdisec
+1
·
Published
2023-11-02
·
Updated
2024-01-12
·
CVE-2023-26454
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
imageconverter service (affected versions not specified)
Description
The issue allows requests to fetch image metadata to be abused, including SQL queries that would be executed unchecked. This requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by default. Arbitrary SQL statements could be executed in the context of the service's database user account. API requests are now properly checked for valid content, and attempts to circumvent this check are being logged as an error.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imageconverter Service