CVE-2023-34752: SQL Injection
Published Jun 14, 2023
·Updated
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.
Affected Software
4 affected components
All of the following
bloofox bloofoxCMS=0.5.2.1
macOS
bloofox bloofoxCMS=0.5.2.1
macOS
Event History
Jun 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-34752.
2
What is the severity of CVE-2023-34752?
The severity of CVE-2023-34752 is critical with a severity value of 9.8.
3
What is the affected software?
The affected software is Bloofox CMS version 0.5.2.1.
4
How does CVE-2023-34752 work?
CVE-2023-34752 allows for SQL injection via the 'lid' parameter at admin/index.php?mode=settings&page=lang&action=edit.
5
How can I fix CVE-2023-34752?
To fix CVE-2023-34752, update to a patched version of Bloofox CMS.