Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Crafter Studio
CVE-2023-26020

5.7MEDIUM

Key Information:

Vendor

Craftercms

Vendor
CVE Published:
17 February 2023

What is CVE-2023-26020?

A vulnerability exists in CrafterCMS that allows attackers to exploit improper neutralization of special elements in SQL commands. This could lead to unauthorized access to sensitive data and disruption of database functionality. The issue affects specific versions of CrafterCMS, including v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1.0 through 3.1.26 on multiple platforms such as Linux, MacOS, Windows, x86, ARM, and 64 bit. It is crucial for users to implement available patches and update to protected versions to mitigate risks.

Affected Version(s)

CrafterCMS Linux 4.0.0 <= 4.0.1

CrafterCMS Linux 3.1.0 <= 3.1.26

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gil Correia <[email protected]>
.