PT-2023-9083 · 3Cx · 3Cx

CVE-2023-49954

·

Publicado

2023-10-11

·

Atualizado

2024-01-03

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions 3CX versions prior to 18.0.9.23 3CX versions 20 prior to 20.0.0.1494
Description The issue is related to a SQL Injection vulnerability in the CRM Integration of 3CX. This vulnerability can be exploited via a first name, search string, or email address, allowing a remote attacker to execute arbitrary SQL queries. The vulnerability is due to the lack of protection of the SQL query structure.
Recommendations For 3CX versions prior to 18.0.9.23, update to version 18.0.9.23 or later to resolve the issue. For 3CX versions 20 prior to 20.0.0.1494, update to version 20.0.0.1494 or later to resolve the issue. As a temporary workaround, consider disabling the SQL Database Integrations to minimize the risk of exploitation.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-03502
CVE-2023-49954

Produtos afetados

3Cx