CVE-2023-34750

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jun 14, 2023
Updated: Jan 2, 2025
CWE ID 89

Summary

CVE-2023-34750 is a recently disclosed SQL injection vulnerability affecting bloofox version 0.5.2.1. This issue can be exploited through the cid parameter in the admin/index.php?mode=settings&page=projects&action=edit URL. An attacker who successfully exploits this vulnerability can gain unauthorized access to sensitive data, modify or delete records, and potentially take control of the affected system. The vulnerability arises due to insufficient input validation and sanitization of user input in the application. Users are encouraged to upgrade to the latest version of bloofox to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share