HIGH
IBOS OA Delete Logs del sql injection
Published Sep 3, 2023
8.8
HIGHCVSS 3.1
EPSS 0.93%
Description
A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects unknown code of the file ?r=diary/default/del of the component Delete Logs Handler. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-238630 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 4.5.5StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54589 Advisory
- https://github.com/wudidike/cve/blob/main/sql.md exploitThird Party Advisory
- https://vuldb.com/?ctiid.238630 signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry
- https://vuldb.com/?id.238630 vdb-entrytechnical-descriptionPermissions RequiredThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54589 | Advisory | |
| https://github.com/wudidike/cve/blob/main/sql.md | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.238630 | signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?id.238630 | vdb-entrytechnical-descriptionPermissions RequiredThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Sep 3, 2023
Updated Oct 1, 2024
Reserved Sep 3, 2023
Link CVE-2023-4741
CISA Vulnrichment
Updated Oct 1, 2024
ENISA EUVD
EUVD-2023-54589 Assigner VulDB
Published Sep 3, 2023
Updated Oct 1, 2024
Exploited since n/a
Link EUVD-2023-54589