Web / CMS
SQL / NoSQL Injection
SQL Injection in Creative Gallery via id parameter
SQL Injection in Creative Gallery via id parameter The Application does not sanitize or escape id parameter, making it vulnerable to sql injection.
9.8
/ 10
Critical
CVSS v3.1
ADVISORY ID
PS82
PUBLISHED
2023-08-16
CVE IDs
CVE-2023-23758
VENDORS
Creative Solutions
PUBLIC EXPLOIT
None indexed
CWE
CWE-89
PRODUCT
Creative Gallery (Joomla)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
.png)
Summary
Overview
SQL Injection in Creative Gallery via id parameter
The Application does not sanitize or escape id parameter, making it vulnerable to sql injection.
Vulnerability details
Vulnerability details
CVE-2023-23758
CWE-89
Critical | 9.8
SQL Injection in Creative Gallery via id parameter The Application does not sanitize or escape id parameter, making it vulnerable to sql injection.
Auth:
None (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
DISCLOSURE
Disclosure timeline
2023-07-06 Reported On
2023-08-07 Made Public On
Fixed On: Not Fixed
References
Credits
Vishal and Siva
















