Web / CMS

SQL / NoSQL Injection

SQL Injection in Creative Gallery via id parameter

SQL Injection in Creative Gallery via id parameter The Application does not sanitize or escape id parameter, making it vulnerable to sql injection.

9.8
/ 10
Critical
CVSS v3.1
ADVISORY ID
PS82
PUBLISHED
2023-08-16
CVE IDs
CVE-2023-23758
VENDORS
Creative Solutions
PUBLIC EXPLOIT
None indexed
CWE
CWE-89
PRODUCT
Creative Gallery (Joomla)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

SQL Injection in Creative Gallery via id parameter

The Application does not sanitize or escape id parameter, making it vulnerable to sql injection.

Vulnerability details

Vulnerability details

CVE-2023-23758
CWE-89
Critical | 9.8

SQL Injection in Creative Gallery via id parameter The Application does not sanitize or escape id parameter, making it vulnerable to sql injection.

Auth:
None (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
DISCLOSURE

Disclosure timeline

2023-07-06 Reported On

2023-08-07 Made Public On

Fixed On: Not Fixed

Credits

Vishal and Siva