CVE-2023-2681

Source
https://cve.org/CVERecord?id=CVE-2023-2681
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-2681.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-2681
Published
2023-10-03T12:19:55Z
Modified
2026-08-27T03:57:00Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
SQL Injection on Jorani
Details

An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote user, with low privileges, to send queries with malicious SQL code on the "/leaves/validate" path and the “id” parameter, managing to extract arbritary information from the database.

Database specific
{
    "cna_assigner": "INCIBE",
    "cwe_ids": [
        "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/2xxx/CVE-2023-2681.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.0.0"
                },
                {
                    "last_affected": "1.0.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/jorani/jorani

Affected ranges

Type
GIT
Repo
https://github.com/jorani/jorani
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:jorani:jorani:1.0.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.0.0"
        },
        {
            "last_affected": "1.0.0"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

1.*
1.0.0
v1.*
v1.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-2681.json"