CVE-2023-33179: Sensitive Information Disclosure abusing SQL Injection in Xibo CMS nameFilter
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.5 in the nameFilter function used throughout the CMS. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values for logical operators. Users should upgrade to version 3.3.5 which fixes this issue. There are no known workarounds aside from upgrading.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Xibo CMSto a version that resolves this vulnerability.Fixed in 3.3.5
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33179?
CVE-2023-33179 is classified as a critical SQL injection vulnerability.
How do I fix CVE-2023-33179?
To mitigate CVE-2023-33179, upgrade Xibo to version 3.3.5 or later.
Who is affected by CVE-2023-33179?
CVE-2023-33179 affects authenticated users of Xibo CMS versions 3.2.0 to 3.3.4.
What is the exploitation method for CVE-2023-33179?
Exploitation of CVE-2023-33179 involves injecting malicious SQL commands through the nameFilter function.
What type of vulnerability is CVE-2023-33179?
CVE-2023-33179 is an SQL injection vulnerability that allows unauthorized data access.