PT-2023-30678 · Cybrosys Techno Solutions · Cybrosys Techno Solutions Website Blog Search

Published

2023-12-14

·

Updated

2023-12-20

·

CVE-2023-48049

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cybrosys Techno Solutions Website Blog Search (aka website search blog) versions 13.0 through 13.0.1.0.1
Description A SQL injection issue allows a remote attacker to execute arbitrary code and gain privileges via the name parameter in the controllers/main.py component.
Recommendations For versions 13.0 through 13.0.1.0.1, consider disabling the name parameter in the controllers/main.py component until a patch is available. Restrict access to the controllers/main.py component to minimize the risk of exploitation. Avoid using the name parameter in the affected component until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-48049

Affected Products

Cybrosys Techno Solutions Website Blog Search