CVE-2024-41803

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-41803
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-41803.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-41803
Aliases
  • GHSA-hpc5-mxfq-44hv
Published
2024-07-30T15:49:51Z
Modified
2025-10-15T12:27:42.000366Z
Severity
  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Xibo allows Sensitive Information Disclosure abusing SQL Injection in Xibo CMS DataSet Filter
Details

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain arbitrary data from the Xibo database by injecting specially crafted values in to the API for viewing DataSet data. Users should upgrade to version 3.3.12 or 4.0.14 which fix this issue.

References

Affected packages

Git / github.com/xibosignage/xibo-cms

Affected ranges

Database specific

{
    "unresolved_versions": [
        {
            "events": [
                {
                    "introduced": "0"
                },
                {
                    "last_affected": "=> 2.1.0, < 3.3.12"
                }
            ],
            "type": ""
        },
        {
            "events": [
                {
                    "introduced": "0"
                },
                {
                    "last_affected": "=> 4.0.0-alpha, < 4.0.14"
                }
            ],
            "type": ""
        }
    ]
}

Git / github.com/xibosignage/xibo-cms

Affected ranges

Type
GIT
Repo
https://github.com/xibosignage/xibo-cms
Events

Affected versions

2.*

2.1.0
2.1.1
2.1.2
2.2.0
2.2.0-alpha
2.2.0-alpha2
2.2.0-beta
2.2.0-rc1
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0-alpha
2.3.0-beta
2.3.0-rc1
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9

3.*

3.0.0
3.0.0-alpha
3.0.0-alpha2
3.0.0-alpha3
3.0.0-beta
3.0.0-rc1
3.0.0-rc2
3.0.0-rc3
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.1.0
3.1.0-alpha
3.1.0-beta
3.1.1
3.1.2
3.1.3
3.1.4
3.2.0
3.2.1
3.3.0
3.3.1
3.3.10
3.3.11
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9

Git / github.com/xibosignage/xibo-cms

Affected ranges

Type
GIT
Repo
https://github.com/xibosignage/xibo-cms
Events

Affected versions

4.*

4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9