Vulnerability Description
A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to read database data via SQL commands injected in the search parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Prolion | Cryptospike | 3.0.15 |
Related Weaknesses (CWE)
References
- https://www.cvcn.gov.it/cvcn/cve/CVE-2023-36652ExploitThird Party Advisory
- https://www.cvcn.gov.it/cvcn/cve/CVE-2023-36652ExploitThird Party Advisory
FAQ
What is CVE-2023-36652?
CVE-2023-36652 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to read database data via SQL commands injected in the search parameter.
How severe is CVE-2023-36652?
CVE-2023-36652 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-36652?
Check the references section above for vendor advisories and patch information. Affected products include: Prolion Cryptospike.