Record summary

CVE-2023-34754 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 2, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALBloofox v0.5.2.1 - SQL InjectionCVSS 9.8

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.

Impact

Allows attackers to execute arbitrary SQL queries, potentially leading to data leakage or data manipulation.

Remediation

Update bloofox to version v0.5.2.2 or later to patch the SQL Injection vulnerability.

WeaknessesCWE-89
Authorsritikchaddha
Template tagstime-based-sqlicvecve2023bloofoxsqliauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:bloofox:bloofoxcms:0.5.2.1:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2