CVE-2023-34754: SQL Injection
Published Jun 14, 2023
·Updated
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.
Affected Software
4 affected components
All of the following
bloofox bloofoxCMS=0.5.2.1
macOS
bloofox bloofoxCMS=0.5.2.1
macOS
Event History
Jun 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-34754?
CVE-2023-34754 is a SQL injection vulnerability found in bloofox v0.5.2.1.
2
How does the SQL injection vulnerability in bloofox v0.5.2.1 work?
The vulnerability occurs through the pid parameter in the admin/index.php?mode=settings&page=plugins&action=edit URL, allowing an attacker to execute malicious SQL queries.
3
What is the severity of CVE-2023-34754?
The severity of CVE-2023-34754 is critical, with a CVSS score of 9.8.
4
Which software versions are affected by CVE-2023-34754?
bloofox v0.5.2.1 is the only affected version.
5
How can I mitigate the SQL injection vulnerability in bloofox v0.5.2.1?
To mitigate the vulnerability, apply the necessary patches or updates provided by the vendor.