CVE-2024-41804

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-41804
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-41804.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-41804
Related
  • GHSA-4pp3-4mw7-qfwr
Published
2024-07-30T16:15:04Z
Modified
2025-01-08T16:19:12.803474Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API route inside the CMS responsible for Adding/Editing DataSet Column Formulas. This allows an authenticated user to to obtain and modify arbitrary data from the Xibo database by injecting specially crafted values in to the formula parameter. Users should upgrade to version 3.3.12 or 4.0.14 which fix this issue.

References

Affected packages

Git / github.com/xibosignage/xibo-cms

Affected ranges

Type
GIT
Repo
https://github.com/xibosignage/xibo-cms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

1.*

1.6.0-rc1
1.7.0
1.7.0-alpha
1.7.0-alpha2
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.0-alpha
1.8.0-alpha2
1.8.0-alpha3
1.8.0-beta
1.8.0-rc1
1.8.0-rc2
1.8.0-rc3
1.8.1
1.8.10
1.8.11
1.8.12
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.8.8
1.8.9

2.*

2.0.0
2.0.0-alpha1
2.0.0-beta
2.0.0-beta.2
2.0.0-rc1
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0-alpha1
2.1.0-alpha2
2.1.0-beta
2.1.0-rc1
2.1.1
2.1.2
2.2.0
2.2.0-alpha
2.2.0-alpha2
2.2.0-beta
2.2.0-rc1
2.2.1
2.2.2
2.2.3
2.3.0-alpha
2.3.0-beta
2.3.0-rc1
2.3.11
2.3.12
2.3.13
2.3.14
2.3.15
2.3.16
2.3.17