CVE-2023-26020
Published on: Not Yet Published
Last Modified on: 02/28/2023 03:52:00 PM UTC
Certain versions of Macos from Apple contain the following vulnerability:
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1.0 through 3.1.26.
- CVE-2023-26020 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
CrafterCMS - CrafterCMS version <= 4.0.1
- Affected Vendor/Software:
CrafterCMS - CrafterCMS version <= 3.1.26
CVSS3 Score: 7.2 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Security Advisories — Crafter CMS 4.0.0 documentation | docs.craftercms.org text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Apple | Macos | - | All | All | All |
Application | Craftercms | Crafter Cms | All | All | All | All |
Application | Craftercms | Crafter Cms | All | All | All | All |
Operating System | Linux | Linux Kernel | - | All | All | All |
Operating System | Microsoft | Windows | - | All | All | All |
- cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*:
- cpe:2.3:a:craftercms:crafter_cms:*:*:*:*:*:*:*:*:
- cpe:2.3:a:craftercms:crafter_cms:*:*:*:*:*:*:*:*:
- cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-26020 : Improper Neutralization of Special Elements used in an SQL Command 'SQL Injection' vulnerability… twitter.com/i/web/status/1… | 2023-02-17 18:06:16 |
![]() |
Potentially Critical CVE Detected! CVE-2023-26020 Improper Neutralization of Special Elements used in an SQL Comman… twitter.com/i/web/status/1… | 2023-02-17 18:56:01 |
![]() |
CVE-2023-26020 | 2023-02-17 19:38:52 |