Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Crafter Studio
CVE-2023-26020
5.7MEDIUM
What is CVE-2023-26020?
A vulnerability exists in CrafterCMS that allows attackers to exploit improper neutralization of special elements in SQL commands. This could lead to unauthorized access to sensitive data and disruption of database functionality. The issue affects specific versions of CrafterCMS, including v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1.0 through 3.1.26 on multiple platforms such as Linux, MacOS, Windows, x86, ARM, and 64 bit. It is crucial for users to implement available patches and update to protected versions to mitigate risks.
Affected Version(s)
CrafterCMS Linux 4.0.0 <= 4.0.1
CrafterCMS Linux 3.1.0 <= 3.1.26
