CVE-2024-41803: Xibo allows Sensitive Information Disclosure abusing SQL Injection in Xibo CMS DataSet Filter
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain arbitrary data from the Xibo database by injecting specially crafted values in to the API for viewing DataSet data. Users should upgrade to version 3.3.12 or 4.0.14 which fix this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41803?
CVE-2024-41803 is considered a high-severity vulnerability due to its potential for SQL injection and unauthorized database access.
How do I fix CVE-2024-41803?
To fix CVE-2024-41803, update Xibo to versions 3.3.12 or 4.0.14 or later, which include the necessary security patches.
Who is affected by CVE-2024-41803?
CVE-2024-41803 affects authenticated users of Xibo versions between 2.1.0 and 3.3.12 as well as versions between 4.0.0 and 4.0.14.
What can an attacker achieve with CVE-2024-41803?
An attacker leveraging CVE-2024-41803 can perform SQL injection to extract arbitrary data from the Xibo database.
Is CVE-2024-41803 specific to any deployment?
CVE-2024-41803 specifically targets deployments of the Xibo content management system that fall within the specified version ranges.