CVE-2023-26443
 
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abused to trigger benign SQL Exceptions but could potentially be escalated to a malicious SQL injection vulnerability. We now properly encode single quotes for SQL FULLTEXT queries. No publicly available exploits are known.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-02-22 CVE Reserved
- 2023-08-02 CVE Published
- 2024-08-02 CVE Updated
- 2025-01-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/173943/OX-App-Suite-SSRF-SQL-Injection-Cross-Site-Scripting.html | Third Party Advisory | |
http://seclists.org/fulldisclosure/2023/Aug/8 | Mailing List | |
https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6230_7.10.6_2023-05-02.pdf | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Backend Search vendor "Open-xchange" for product "Open-xchange Appsuite Backend" | <= 7.10.6 Search vendor "Open-xchange" for product "Open-xchange Appsuite Backend" and version " <= 7.10.6" | - |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Backend Search vendor "Open-xchange" for product "Open-xchange Appsuite Backend" | >= 8.10.0 <= 8.12 Search vendor "Open-xchange" for product "Open-xchange Appsuite Backend" and version " >= 8.10.0 <= 8.12" | - |
Affected
|