CVE-2023-33180

Source
https://cve.org/CVERecord?id=CVE-2023-33180
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-33180.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-33180
Aliases
  • GHSA-7ww5-x9rm-qm89
Published
2023-05-30T20:18:40.895Z
Modified
2026-04-10T04:58:45.457864Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Sensitive Information Disclosure abusing SQL Injection in Xibo CMS display map
Details

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.2 in the /display/map API route inside the CMS. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values in to the bounds parameter. Users should upgrade to version 3.3.5, which fixes this issue. There are no known workarounds aside from upgrading.

Database specific
{
    "cwe_ids": [
        "CWE-89"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/33xxx/CVE-2023-33180.json"
}
References

Affected packages

Git / github.com/xibosignage/xibo-cms

Affected ranges

Type
GIT
Repo
https://github.com/xibosignage/xibo-cms
Events

Affected versions

3.*
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-33180.json"