PT-2024-29570 · Xibo · Xibo

Sergey Bobrov

·

Published

2024-07-30

·

Updated

2024-08-23

·

CVE-2024-41803

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xibo versions prior to 3.3.12 Xibo versions prior to 4.0.14
Description A SQL injection issue was discovered in the API routes of Xibo, a content management system, specifically in the components responsible for filtering DataSets. This allows an authenticated user to obtain arbitrary data from the Xibo database by injecting specially crafted values into the API for viewing DataSet data.
Recommendations For versions prior to 3.3.12, upgrade to version 3.3.12 to resolve the issue. For versions prior to 4.0.14, upgrade to version 4.0.14 to resolve the issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-41803
GHSA-HPC5-MXFQ-44HV

Affected Products

Xibo