S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 9, 2024

CVE-2023-34756 Scanner

CVE-2023-34756 scanner - SQL Injection vulnerability in Bloofox

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-34756
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Bloofox CMS is an open-source content management system designed for the easy creation and management of websites. It caters to both individual and business needs, providing tools for website development without requiring in-depth programming knowledge. Bloofox is utilized for its user-friendly interface and flexible customization options, making it suitable for various types of web projects.

The CVE-2023-34756 vulnerability in Bloofox v0.5.2.1 is a critical SQL Injection flaw that allows attackers to execute arbitrary SQL commands through the cid parameter in the charset editing functionality of the admin panel. This security flaw poses a significant risk as it can lead to unauthorized access, data leakage, and even full system compromise.

The vulnerability is present in the admin/index.php file when accessing the charset edit page (mode=settings&page=charset&action=edit). Due to insufficient validation of user input for the cid parameter, attackers can inject malicious SQL statements, compromising the database integrity and bypassing authentication mechanisms.

Exploitation of this vulnerability can lead to unauthorized data access, manipulation of database entries, disclosure of sensitive information, and potentially, control over the affected CMS. This could have severe implications for data confidentiality, website integrity, and user trust.

By leveraging S4E's advanced scanning capabilities, users can identify vulnerabilities like CVE-2023-34756 in Bloofox CMS early on. Our platform provides detailed insights and remediation guidelines to help secure your digital assets against potential threats, enhancing overall security posture and compliance.

 

References

Solution Advice
  1. Immediately update Bloofox CMS to the latest version that addresses this SQL Injection vulnerability.
  2. Employ comprehensive input validation techniques to mitigate SQL Injection risks.
  3. Regularly perform security audits and assessments to identify and rectify potential vulnerabilities.
  4. Educate users and administrators about the importance of security practices and maintaining up-to-date software.
  5. Utilize web application firewalls (WAFs) and other security measures to provide an additional layer of protection against exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-34756 scanner - SQL Injection vulnerability in Bloofox | S4E