Record summary

CVE-2023-34751 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 2, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALbloofoxCMS v0.5.2.1 - SQL InjectionCVSS 9.8

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.

Impact

Authenticated attackers can exploit time-based SQL injection in the gid parameter to extract sensitive database information including user credentials, group permissions, and CMS configuration data from the Bloofox system.

Remediation

Update Bloofox to a version newer than 0.5.2.1 that uses parameterized queries and properly validates the gid parameter in the groups edit functionality.

WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicve2023cvesqlibloofoxauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:bloofox:bloofoxcms:0.5.2.1:*:*:*:*:*:*:*
FOFA: Powered by bloofoxCMS
FOFA: powered by bloofoxcms

Source: ProjectDiscovery

References

2