Vulnerability Description
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bloofox | Bloofoxcms | 0.5.2.1 |
| Apple | Macos | - |
Related Weaknesses (CWE)
References
- https://ndmcyb.hashnode.dev/bloofox-v0521-was-discovered-to-contain-many-sql-injExploitThird Party Advisory
- https://ndmcyb.hashnode.dev/bloofox-v0521-was-discovered-to-contain-many-sql-injExploitThird Party Advisory
FAQ
What is CVE-2023-34751?
CVE-2023-34751 is a vulnerability with a CVSS score of 9.8 (CRITICAL). bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.
How severe is CVE-2023-34751?
CVE-2023-34751 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-34751?
Check the references section above for vendor advisories and patch information. Affected products include: Bloofox Bloofoxcms, Apple Macos.