Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-30272 | Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by default. Arbitrary SQL statements could be executed in the context of the services database user account. API requests are now properly checked for valid content and attempts to circumvent this check are being logged as error. No publicly available exploits are known. |
No history.
Status: PUBLISHED
Assigner: OX
Published:
Updated: 2024-08-02T11:53:52.901Z
Reserved: 2023-02-22T20:42:56.092Z
Link: CVE-2023-26452
No data.
Status : Modified
Published: 2023-11-02T14:15:10.647
Modified: 2026-06-17T05:43:21.833
Link: CVE-2023-26452
No data.
OpenCVE Enrichment
No data.
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
EUVD