CVE-2023-2188: Colibri Page Builder <= 1.0.227 - Authenticated (Administrator+) SQL Injection via post_id
The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘postid’ parameter in versions up to, and including, 1.0.227 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrator-level privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2188?
CVE-2023-2188 is rated as a high severity vulnerability due to the potential for SQL injection exploitation.
How do I fix CVE-2023-2188?
To fix CVE-2023-2188, upgrade the Colibri Page Builder plugin to version 1.0.229 or higher.
What versions are affected by CVE-2023-2188?
CVE-2023-2188 affects all versions of the Colibri Page Builder for WordPress up to and including 1.0.227.
What kind of attack does CVE-2023-2188 allow?
CVE-2023-2188 allows authenticated users to perform SQL injection attacks through the 'post_id' parameter.
Is authentication required to exploit CVE-2023-2188?
Yes, exploitation of CVE-2023-2188 requires an authenticated user to access the vulnerable parameter.