PT-2023-9083 · 3Cx · 3Cx

Published

2023-10-11

·

Updated

2024-01-03

·

CVE-2023-49954

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions 3CX versions prior to 18.0.9.23 3CX versions 20 prior to 20.0.0.1494
Description The issue is related to a SQL Injection vulnerability in the CRM Integration of 3CX. This vulnerability can be exploited via a first name, search string, or email address, allowing a remote attacker to execute arbitrary SQL queries. The vulnerability is due to the lack of protection of the SQL query structure.
Recommendations For 3CX versions prior to 18.0.9.23, update to version 18.0.9.23 or later to resolve the issue. For 3CX versions 20 prior to 20.0.0.1494, update to version 20.0.0.1494 or later to resolve the issue. As a temporary workaround, consider disabling the SQL Database Integrations to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2024-03502
CVE-2023-49954

Affected Products

3Cx