PT-2023-24197 · Xibo · Xibo

Noam Moshe

·

Published

2023-05-30

·

Updated

2023-06-06

·

CVE-2023-33180

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xibo versions 3.2.0 through 3.3.2
Description A SQL injection issue was discovered in the /display/map API route, allowing an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values into the bounds parameter.
Recommendations For versions 3.2.0 through 3.3.2, upgrade to version 3.3.5 to resolve the issue. As a temporary workaround, consider restricting access to the /display/map API route until the upgrade is applied. Avoid using the bounds parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-33180
GHSA-7WW5-X9RM-QM89

Affected Products

Xibo