CVE-2024-41803

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain arbitrary data from the Xibo database by injecting specially crafted values in to the API for viewing DataSet data. Users should upgrade to version 3.3.12 or 4.0.14 which fix this issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xibosignage:xibo:*:*:*:*:*:*:*:*
cpe:2.3:a:xibosignage:xibo:*:*:*:*:*:*:*:*

History

23 Aug 2024, 13:41

Type Values Removed Values Added
First Time Xibosignage xibo
Xibosignage
References () https://github.com/xibosignage/xibo-cms/commit/39a2fd54b3f08831b0004aa2015bd8a753bc567f.patch - () https://github.com/xibosignage/xibo-cms/commit/39a2fd54b3f08831b0004aa2015bd8a753bc567f.patch - Patch, Vendor Advisory
References () https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-hpc5-mxfq-44hv - () https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-hpc5-mxfq-44hv - Patch, Vendor Advisory
References () https://xibosignage.com/blog/security-advisory-2024-07 - () https://xibosignage.com/blog/security-advisory-2024-07 - Vendor Advisory
CPE cpe:2.3:a:xibosignage:xibo:*:*:*:*:*:*:*:*

31 Jul 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Xibo es un sistema de gestión de contenidos (CMS). Se descubrió una vulnerabilidad de inyección SQL en las rutas API dentro del CMS responsable del filtrado de conjuntos de datos. Esto permite a un usuario autenticado obtener datos arbitrarios de la base de datos Xibo inyectando valores especialmente manipulados en la API para ver los datos del DataSet. Los usuarios deben actualizar a la versión 3.3.12 o 4.0.14, que soluciona este problema.

30 Jul 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-30 16:15

Updated : 2024-08-23 13:41


NVD link : CVE-2024-41803

Mitre link : CVE-2024-41803

CVE.ORG link : CVE-2024-41803


JSON object : View

Products Affected

xibosignage

  • xibo
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')