CVE-2024-41802: Xibo allows Sensitive Information Disclosure abusing SQL Injection in Xibo CMS DataSet Data Import
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to the APIs for importing JSON and importing a Layout containing DataSet data. Users should upgrade to version 3.3.12 or 4.0.14 which fix this issue
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41802?
CVE-2024-41802 is considered a high severity vulnerability due to its potential for SQL injection attacks that can lead to unauthorized data access and modification.
How do I fix CVE-2024-41802?
To fix CVE-2024-41802, update your Xibo installation to versions 3.3.12 or later, or 4.0.14 or later.
Who is affected by CVE-2024-41802?
CVE-2024-41802 affects users of Xibo versions between 2.1.0 to 3.3.12 and 4.0.0 to 4.0.14.
What can happen if CVE-2024-41802 is exploited?
If exploited, CVE-2024-41802 can allow an attacker to execute arbitrary SQL queries, potentially compromising sensitive data within the Xibo database.
Is authentication required to exploit CVE-2024-41802?
Yes, exploitation of CVE-2024-41802 requires that the attacker be an authenticated user of the Xibo CMS.