CVE-2023-49954: SQL Injection
Published Dec 25, 2023
·Updated
The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address.
Affected Software
2 affected components
3CX 3CX<18.0.9.23
3CX 3CX>=20.0<20.0.0.1494
Event History
Dec 15, 2023
News Published
05:30 PM
Dec 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49954?
CVE-2023-49954 is classified as a critical vulnerability due to its potential for SQL Injection.
2
How do I fix CVE-2023-49954?
To fix CVE-2023-49954, update to 3CX version 18.0.9.23 or later, or version 20.0.0.1494 or later.
3
What does CVE-2023-49954 affect?
CVE-2023-49954 affects the CRM Integration in 3CX versions prior to 18.0.9.23 and 20 versions before 20.0.0.1494.
4
What type of attack can CVE-2023-49954 lead to?
CVE-2023-49954 can lead to SQL Injection attacks, allowing unauthorized access to the database.
5
Who is affected by CVE-2023-49954?
Organizations using affected versions of 3CX are at risk from CVE-2023-49954.