CVE-2023-26443
02.08.2023, 13:15
Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abused to trigger benign SQL Exceptions but could potentially be escalated to a malicious SQL injection vulnerability. We now properly encode single quotes for SQL FULLTEXT queries. No publicly available exploits are known.
Vendor | Product | Version |
---|---|---|
open-xchange | open-xchange_appsuite_backend | 𝑥 ≤ 7.10.6 |
open-xchange | open-xchange_appsuite_backend | 8.10.0 ≤ 𝑥 ≤ 8.12 |
𝑥
= Vulnerable software versions
References