CRITICAL
IBOS OA del sql injection
Published Sep 9, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.74%
Description
A vulnerability, which was classified as critical, was found in IBOS OA 4.5.5. This affects an unknown part of the file ?r=dashboard/position/del. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239259.
Affected products
-
- Version 4.5.5StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54691 Advisory
- https://github.com/RCEraser/cve/blob/main/sql_inject_2.md exploitThird Party Advisory
- https://vuldb.com/?ctiid.239259 signaturepermissions-requiredThird Party Advisory
- https://vuldb.com/?id.239259 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54691 | Advisory | |
| https://github.com/RCEraser/cve/blob/main/sql_inject_2.md | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.239259 | signaturepermissions-requiredThird Party Advisory | |
| https://vuldb.com/?id.239259 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Sep 9, 2023
Updated Aug 2, 2024
Reserved Sep 8, 2023
Link CVE-2023-4850
CISA Vulnrichment
Updated Jul 8, 2024
ENISA EUVD
EUVD-2023-54691 Assigner VulDB
Published Sep 9, 2023
Updated Aug 2, 2024
Exploited since n/a
Link EUVD-2023-54691