CVE-2023-34756

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jun 14, 2023
Updated: Jan 3, 2025
CWE ID 89

Summary

CVE-2023-34756 is a newly disclosed SQL injection vulnerability affecting the bloofox v0.5.2.1 system. The issue lies in the admin/index.php file, specifically the settings page under the charset tab and the action parameter named 'edit'. An attacker can manipulate the cid parameter to inject malicious SQL commands, potentially gaining unauthorized access to sensitive data or even taking control of the affected system. This vulnerability underscores the importance of maintaining up-to-date software and implementing input validation techniques to prevent SQL injection attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share