CVE-2023-33180: Sensitive Information Disclosure abusing SQL Injection in Xibo CMS display map
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.2 in the /display/map API route inside the CMS. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values in to the bounds parameter. Users should upgrade to version 3.3.5, which fixes this issue. There are no known workarounds aside from upgrading.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Xibo CMSto a version that resolves this vulnerability.Fixed in 3.3.5
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33180?
CVE-2023-33180 is considered a high severity SQL injection vulnerability that can lead to unauthorized data access.
How do I fix CVE-2023-33180?
To fix CVE-2023-33180, upgrade to Xibo version 3.3.2 or later.
Who is affected by CVE-2023-33180?
CVE-2023-33180 affects authenticated users of Xibo versions 3.2.0 to 3.3.1.
What types of attacks can CVE-2023-33180 enable?
CVE-2023-33180 can enable attackers to perform SQL injection, potentially allowing data exfiltration from the Xibo database.
When was CVE-2023-33180 discovered?
CVE-2023-33180 was discovered in May 2023.