CVE-2023-34756: SQL Injection
Published Jun 14, 2023
·Updated
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.
Affected Software
4 affected components
All of the following
bloofox bloofoxCMS=0.5.2.1
macOS
bloofox bloofoxCMS=0.5.2.1
macOS
Event History
Jun 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-34756?
CVE-2023-34756 is a SQL injection vulnerability in bloofox v0.5.2.1.
2
How does CVE-2023-34756 affect bloofox v0.5.2.1?
CVE-2023-34756 allows attackers to execute arbitrary SQL queries via the cid parameter in the admin settings page.
3
What is the severity of CVE-2023-34756?
CVE-2023-34756 has a severity rating of 9.8 (critical).
4
How can I fix CVE-2023-34756?
To fix CVE-2023-34756, update bloofox to a version that does not contain the SQL injection vulnerability.
5
Where can I find more information about CVE-2023-34756?
You can find more information about CVE-2023-34756 at this link: https://ndmcyb.hashnode.dev/bloofox-v0521-was-discovered-to-contain-many-sql-injection-vulnerability