CVE-2023-45674
SQL injection vulnerability in Farmbot-Web-App
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Farmbot-Web-App is a web control interface for the Farmbot farm automation platform. An SQL injection vulnerability was found in FarmBot's web app that allows authenticated attackers to extract arbitrary data from its database (including the user table). This issue may lead to Information Disclosure. This issue has been patched in version 15.8.4. Users are advised to upgrade. There are no known workarounds for this issue.
Farmbot-Web-App es una interfaz de control web para la plataforma de automatización agrícola Farmbot. Se encontró una vulnerabilidad de inyección SQL en la aplicación web de FarmBot que permite a atacantes autenticados extraer datos arbitrarios de su base de datos (incluida la tabla de usuarios). Este problema puede dar lugar a la divulgación de información. Este problema se solucionó en la versión 15.8.4. Se recomienda a los usuarios que actualicen. No se conocen workarounds para este problema.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-10-10 CVE Reserved
- 2023-10-13 CVE Published
- 2024-09-16 CVE Updated
- 2024-10-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/FarmBot/Farmbot-Web-App/security/advisories/GHSA-pgq5-ff74-g7xq | 2023-10-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Farmbot Search vendor "Farmbot" | Farmbot Web App Search vendor "Farmbot" for product "Farmbot Web App" | < 15.8.4 Search vendor "Farmbot" for product "Farmbot Web App" and version " < 15.8.4" | - |
Affected
|