Record summary

CVE-2023-36284 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 29, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryHIGHQloApps 1.6.0 - SQL InjectionCVSS 7.5

An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameters date_from, date_to, and id_product allows a remote attacker to retrieve the contents of an entire database.

Impact

Successful exploitation could lead to unauthorized access to sensitive data.

Remediation

Apply the vendor-supplied patch or upgrade to a non-vulnerable version.

WeaknessesCWE-89
Authorsritikchaddha
Template tagstime-based-sqlicvecve2023qloappssqliwebkulvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:webkul:qloapps:1.6.0:*:*:*:*:*:*:*
FOFA: title="QloApps"
FOFA: title="qloapps"

Source: ProjectDiscovery

References

2