CVE-2023-29047
MEDIUMImageconverter - SQL Injection
Title source: llmDescription
Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements. An attacker with access to the adjacent network and potentially API credentials, could read and modify database content which is accessible to the imageconverter SQL user account. None No publicly available exploits are known.
Scores
CVSS v3
5.3
EPSS
0.0005
EPSS Percentile
15.2%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Classification
CWE
CWE-89
Status
published
Affected Products (43)
open-xchange/open-xchange_appsuite
< 7.10.6
open-xchange/open-xchange_appsuite
open-xchange/open-xchange_appsuite
open-xchange/open-xchange_appsuite
open-xchange/open-xchange_appsuite
open-xchange/open-xchange_appsuite
open-xchange/open-xchange_appsuite
open-xchange/open-xchange_appsuite
open-xchange/open-xchange_appsuite
open-xchange/open-xchange_appsuite
open-xchange/open-xchange_appsuite
open-xchange/open-xchange_appsuite
open-xchange/open-xchange_appsuite
open-xchange/open-xchange_appsuite
open-xchange/open-xchange_appsuite
... and 28 more
Timeline
Published
Nov 02, 2023
Tracked Since
Feb 18, 2026