First published: Fri Oct 13 2023(Updated: )
Farmbot-Web-App is a web control interface for the Farmbot farm automation platform. An SQL injection vulnerability was found in FarmBot's web app that allows authenticated attackers to extract arbitrary data from its database (including the user table). This issue may lead to Information Disclosure. This issue has been patched in version 15.8.4. Users are advised to upgrade. There are no known workarounds for this issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Farmers Wife | <15.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-45674.
The title of the vulnerability is 'Farmbot-Web-App SQL injection vulnerability'.
Farmbot-Web-App is a web control interface for the Farmbot farm automation platform.
The severity of CVE-2023-45674 is high with a CVSS score of 6.5.
The affected software is Farmbot-Web-App version up to 15.8.4.
The SQL injection vulnerability in Farmbot-Web-App allows authenticated attackers to extract arbitrary data from its database, including the user table.
The SQL injection vulnerability in Farmbot-Web-App may lead to information disclosure.
To fix CVE-2023-45674, update Farmbot-Web-App to a version beyond 15.8.4.
You can find more information about CVE-2023-45674 at the following reference: [GitHub Advisory](https://github.com/FarmBot/Farmbot-Web-App/security/advisories/GHSA-pgq5-ff74-g7xq).
The CWE ID associated with CVE-2023-45674 is CWE-89 (SQL Injection).