critical·Product Based Web Vulnerabilities·Updated Mar 9, 2024

CVE-2023-34751 Scanner

CVE-2023-34751 scanner - SQL Injection vulnerability in bloofoxCMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
14
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-34751
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

bloofoxCMS is an open-source content management system (CMS) designed for creating and managing websites efficiently. It is developed by the bloofox project, offering a user-friendly interface, flexibility, and a variety of features for web administrators. This CMS is particularly suitable for small to medium-sized websites and is valued for its simplicity, modular design, and lightweight architecture. The software facilitates content creation, editing, and organization, providing tools for user management, media handling, and template customization.

CVE-2023-34751 exposes a critical SQL Injection vulnerability within bloofoxCMS version 0.5.2.1. This security flaw allows attackers to execute arbitrary SQL commands through the 'gid' parameter in the admin panel under 'user/groups/edit'. Such vulnerabilities pose a severe risk as they can lead to unauthorized database access, data theft, and in some cases, complete system compromise. This vulnerability underscores the necessity of proper input validation and sanitization in web applications.

The SQL Injection vulnerability is found in the admin/index.php file, particularly when editing user groups. The 'gid' parameter lacks sufficient input validation, enabling attackers to inject malicious SQL code. By crafting a malicious request, an attacker can manipulate database queries, leading to unauthorized access to sensitive information or modification of data. Exploitation of this vulnerability requires access to the admin panel, which highlights the importance of securing administrative interfaces.

If exploited, the vulnerability could lead to severe consequences including data breaches, unauthorized access to sensitive information, and potential control over the CMS. Attackers could leverage this flaw to escalate privileges, manipulate content, or even deploy malicious code, impacting the integrity and availability of the affected website. The breach of trust and potential legal ramifications make this a critical concern for users of the affected versions of bloofoxCMS.

S4E provides a comprehensive platform to identify and mitigate vulnerabilities like CVE-2023-34751 in bloofoxCMS. By using our cyber threat exposure management service, users can benefit from detailed vulnerability scans, real-time monitoring, and actionable insights to enhance their digital security posture. Our platform offers tailored recommendations for remediation, helping businesses protect their assets and maintain the trust of their stakeholders. Join us to secure your online presence against evolving cyber threats.

 

References

Solution Advice
  1. Immediately update bloofoxCMS to the latest version that addresses this vulnerability.
  2. Conduct a thorough security review and apply necessary patches to vulnerable components.
  3. Ensure input validation and sanitization practices are implemented to prevent SQL injection attacks.
  4. Limit access to the administrative interface to trusted IP addresses and use strong, unique passwords for admin accounts.
  5. Regularly monitor and audit system logs for suspicious activities indicative of attempted or successful exploitation.
  6. Consider using web application firewalls (WAFs) and security plugins to further protect against SQL injection and other web-based attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-34751 scanner - SQL Injection vulnerability in bloofoxCMS S4E