CVE-2023-29047 — SQL Injection in Appsuite
Severity
7.3HIGHNVD
CNA5.3
EPSS
0.1%
top 84.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 2
Description
Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements. An attacker with access to the adjacent network and potentially API credentials, could read and modify database content which is accessible to the imageconverter SQL user account. None No publicly available exploits are known.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.1 | Impact: 5.2
Affected Packages2 packages
🔴Vulnerability Details
2CVEList▶
CVE-2023-29047: Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL stat↗2023-11-02
GHSA▶
GHSA-c568-gcr5-3gmw: Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL stat↗2023-11-02