CVE-2023-26443
CVSS V2 None
CVSS V3 None
Description
Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abused to trigger benign SQL Exceptions but could potentially be escalated to a malicious SQL injection vulnerability. We now properly encode single quotes for SQL FULLTEXT queries. No publicly available exploits are known.
Overview
- CVE ID
- CVE-2023-26443
- Assigner
- OX
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-08-02T12:23:17.319Z
- Last Modified Date
- 2024-01-12T07:09:45.991Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-26443 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26443 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-24 23:11:56 | Added to TrackCVE |