CVE-2023-26443
low-risk
Published 2023-08-02
Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abused to trigger benign SQL Exceptions but could potentially be escalated to a malicious SQL injection vulnerability. We now properly encode single quotes for SQL FULLTEXT queries. No publicly available exploits are known.
Do I need to act?
-
0.05% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.5/10
Medium
NETWORK
/ HIGH complexity
Affected Products (1)
Open-Xchange Appsuite Backend
Affected Vendors
References (8)
Third Party Advisory
http://packetstormsecurity.com/files/173943/OX-App-Suite-SSRF-SQL-Injection-Cros...
Mailing List
http://seclists.org/fulldisclosure/2023/Aug/8
Third Party Advisory
http://packetstormsecurity.com/files/173943/OX-App-Suite-SSRF-SQL-Injection-Cros...
Mailing List
http://seclists.org/fulldisclosure/2023/Aug/8
22
/ 100
low-risk
Severity
17/34 · Moderate
Exploitability
0/34 · Minimal
Exposure
5/34 · Minimal