PT-2023-9083 · 3Cx · 3Cx
CVE-2023-49954
·
Publicado
2023-10-11
·
Atualizado
2024-01-03
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
3CX versions prior to 18.0.9.23
3CX versions 20 prior to 20.0.0.1494
Description
The issue is related to a SQL Injection vulnerability in the CRM Integration of 3CX. This vulnerability can be exploited via a first name, search string, or email address, allowing a remote attacker to execute arbitrary SQL queries. The vulnerability is due to the lack of protection of the SQL query structure.
Recommendations
For 3CX versions prior to 18.0.9.23, update to version 18.0.9.23 or later to resolve the issue.
For 3CX versions 20 prior to 20.0.0.1494, update to version 20.0.0.1494 or later to resolve the issue.
As a temporary workaround, consider disabling the SQL Database Integrations to minimize the risk of exploitation.
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
3Cx