PT-2023-8132 · Unknown · Springblade

Cyvk

·

Published

2023-08-29

·

Updated

2024-01-07

·

CVE-2023-40787

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SpringBlade version 3.6.0
Description The issue is related to the lack of protection against SQL query structure exploitation, allowing a remote attacker to execute arbitrary SQL queries. Specifically, in SpringBlade, when executing SQL queries, the parameters submitted by the user are not wrapped in quotation marks, leading to SQL injection.
Recommendations For SpringBlade version 3.6.0, consider disabling the execution of user-submitted SQL queries until a patch is available, or ensure that all user-submitted parameters are properly sanitized and wrapped in quotation marks to prevent SQL injection.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-00111
CVE-2023-40787
GHSA-62PR-54GV-VG5G

Affected Products

Springblade