CVE-2023-3624: Nesote Inout Blockchain FiatExchanger POST Parameter update_marketboxslider sql injection
A vulnerability classified as critical has been found in Nesote Inout Blockchain FiatExchanger 3.0. This affects an unknown part of the file /index.php/coins/updatemarketboxslider of the component POST Parameter Handler. The manipulation of the argument marketcurrency leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-233577 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3624?
CVE-2023-3624 is classified as a critical vulnerability.
How do I fix CVE-2023-3624?
To fix CVE-2023-3624, ensure that you patch the Nesote Inout Blockchain FiatExchanger to the latest version that addresses this vulnerability.
What component is affected by CVE-2023-3624?
CVE-2023-3624 affects the POST Parameter Handler in the file /index.php/coins/update_marketboxslider.
What kind of attack can CVE-2023-3624 facilitate?
CVE-2023-3624 can facilitate SQL injection attacks due to improper handling of the marketcurrency parameter.
Which software version is impacted by CVE-2023-3624?
CVE-2023-3624 impacts version 3.0 of Nesote Inout Blockchain FiatExchanger.