CVE-2023-34750
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2023-34750 is a recently disclosed SQL injection vulnerability affecting bloofox version 0.5.2.1. This issue can be exploited through the cid parameter in the admin/index.php?mode=settings&page=projects&action=edit URL. An attacker who successfully exploits this vulnerability can gain unauthorized access to sensitive data, modify or delete records, and potentially take control of the affected system. The vulnerability arises due to insufficient input validation and sanitization of user input in the application. Users are encouraged to upgrade to the latest version of bloofox to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.