CVE-2024-41804: Xibo allows Sensitive Information Disclosure abusing SQL Injection in Xibo CMS DataSet Column Formula
Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API route inside the CMS responsible for Adding/Editing DataSet Column Formulas. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to the formula parameter. Users should upgrade to version 3.3.12 or 4.0.14 which fix this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41804?
CVE-2024-41804 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2024-41804?
To fix CVE-2024-41804, update to the latest version of Xibo that addresses this vulnerability.
Who is affected by CVE-2024-41804?
CVE-2024-41804 affects Xibo versions between 2.1.0 and 3.3.12 as well as versions between 4.0.0 and 4.0.14.
What can be exploited in CVE-2024-41804?
CVE-2024-41804 allows authenticated users to perform SQL injection attacks via the API route for Adding/Editing DataSet Column Formulas.
What are the potential impacts of CVE-2024-41804?
Exploitation of CVE-2024-41804 can lead to unauthorized access and modification of arbitrary data in the Xibo database.