First published: Wed Jun 14 2023(Updated: )
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bloofox Bloofoxcms | =0.5.2.1 | |
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34756 is a SQL injection vulnerability in bloofox v0.5.2.1.
CVE-2023-34756 allows attackers to execute arbitrary SQL queries via the cid parameter in the admin settings page.
CVE-2023-34756 has a severity rating of 9.8 (critical).
To fix CVE-2023-34756, update bloofox to a version that does not contain the SQL injection vulnerability.
You can find more information about CVE-2023-34756 at this link: https://ndmcyb.hashnode.dev/bloofox-v0521-was-discovered-to-contain-many-sql-injection-vulnerability