CVE-2023-7333

MEDIUM

Pypi Records-mover < 1.6.0 - Injection

Title source: rule
STIX 2.1

Description

A weakness has been identified in bluelabsio records-mover up to 1.5.4. The affected element is an unknown function of the component Table Object Handler. This manipulation causes sql injection. The attack needs to be launched locally. Upgrading to version 1.6.0 is sufficient to fix this issue. Patch name: 3f8383aa89f45d861ca081e3e9fd2cc9d0b5dfaa. You should upgrade the affected component.

References (6)

Core 6

Scores

CVSS v3 5.3
EPSS 0.0001
EPSS Percentile 0.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (7)
bluelabsio/records-mover 1.5.0
bluelabsio/records-mover 1.5.1
bluelabsio/records-mover 1.5.2
bluelabsio/records-mover 1.5.3
bluelabsio/records-mover 1.5.4
bluelabsio/records-mover 1.6.0
pypi/records-mover 0 - 1.6.0PyPI
Published Jan 07, 2026
Tracked Since Feb 18, 2026