ndmcyb.hashnode.dev
https://ndmcyb.hashnode.dev/bloofox-v0521-was-discovered-to-contain-many-sql-injection-vulnerability CVE-2023-34754
CRITICALNuclei
Bloofox v0.5.2.1 - SQL Injection
Record summary
CVE-2023-34754 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 2, 2025 · Source: CVE List
Nuclei templates
1ProjectDiscoveryCRITICALBloofox v0.5.2.1 - SQL InjectionCVSS 9.8
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.
Impact
Allows attackers to execute arbitrary SQL queries, potentially leading to data leakage or data manipulation.
Remediation
Update bloofox to version v0.5.2.2 or later to patch the SQL Injection vulnerability.
WeaknessesCWE-89
Authorsritikchaddha
Template tagstime-based-sqlicvecve2023bloofoxsqliauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:bloofox:bloofoxcms:0.5.2.1:*:*:*:*:*:*:*
https://ndmcyb.hashnode.dev/T-v0521-was-discovered-to-contain-many-sql-injection-vulnerability https://nvd.nist.gov/vuln/detail/CVE-2023-34754
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-34754