PT-2023-8132 · Unknown · Springblade

·

CVE-2023-40787

·

Published

2023-08-29

·

Updated

2024-01-07

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SpringBlade version 3.6.0
Description The issue is related to the lack of protection against SQL query structure exploitation, allowing a remote attacker to execute arbitrary SQL queries. Specifically, in SpringBlade, when executing SQL queries, the parameters submitted by the user are not wrapped in quotation marks, leading to SQL injection.
Recommendations For SpringBlade version 3.6.0, consider disabling the execution of user-submitted SQL queries until a patch is available, or ensure that all user-submitted parameters are properly sanitized and wrapped in quotation marks to prevent SQL injection.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00111
CVE-2023-40787
GHSA-62PR-54GV-VG5G

Affected Products

Springblade