CVE-2023-34756
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jun 14, 2023
Updated: Jun 17, 2023
CWE ID 89
Summary
CVE-2023-34756 refers to a SQL injection vulnerability found in bloofox v0.5.2.1. An attacker can exploit this issue by manipulating the cid parameter in the admin/index.php?mode=settings&page=charset&action=edit URL. Successful exploitation could allow the attacker to execute malicious SQL statements, potentially leading to unauthorized access to sensitive data or system control. Users are advised to upgrade to the latest version of bloofox to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share