PT-2023-24195 · Xibo · Xibo

Noam Moshe

·

Published

2023-05-30

·

Updated

2023-06-06

·

CVE-2023-33179

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xibo versions 3.2.0 through 3.3.4
Description A SQL injection issue was discovered in the nameFilter function, allowing an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values for logical operators.
Recommendations For versions 3.2.0 through 3.3.4, upgrade to version 3.3.5 to resolve the issue. As a temporary workaround, consider restricting access to the nameFilter function until the upgrade to version 3.3.5 is completed.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-33179
GHSA-JMX8-CGM4-7MF5

Affected Products

Xibo