S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 9, 2024

CVE-2023-34752 Scanner

CVE-2023-34752 scanner - SQL Injection vulnerability in bloofoxCMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-34752
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

bloofoxCMS is a lightweight, user-friendly content management system designed for individuals and businesses to create and manage their web presence. Developed by bloofox, it offers an array of features for website content management including customizable templates, multimedia support, and user management. The CMS is ideal for small to medium-sized websites, providing a simple yet powerful platform for web developers and content creators. Its open-source nature allows for customization and community-driven enhancements, making it a versatile tool for web projects.

CVE-2023-34752 reveals a critical SQL Injection vulnerability in bloofoxCMS version 0.5.2.1. This flaw enables attackers to execute arbitrary SQL commands through the 'lid' parameter in the language settings editing feature within the admin panel. SQL Injection vulnerabilities are severe because they can lead to unauthorized database access, data exfiltration, and even control over the affected web application. The exploitation of this vulnerability undermines the security and integrity of the CMS.

The vulnerability is present in the admin/index.php file when performing operations on the language settings (mode=settings&page=lang&action=edit). Specifically, the 'lid' parameter does not undergo adequate input sanitization, allowing for SQL code injection. Malicious actors can exploit this to manipulate the underlying database queries, potentially accessing or modifying data without authorization. This highlights the critical need for secure coding practices, including the proper sanitization of user inputs.

Exploiting the SQL Injection vulnerability in bloofoxCMS could have dire consequences, including unauthorized access to sensitive information, alteration or deletion of data, and potential takeover of the CMS. Such breaches can lead to loss of reputation, legal issues, and financial losses for affected parties. It underscores the importance of robust security measures in web applications to protect against such vulnerabilities.

At S4E, we offer an advanced Cyber Threat Exposure Management service that can detect vulnerabilities like CVE-2023-34752 in bloofoxCMS. By leveraging our platform, users gain access to comprehensive scanning tools that identify potential security flaws in their digital infrastructure. Our service provides actionable insights and recommendations for remediation, helping businesses safeguard their digital assets against emerging threats. Join us and enhance your cybersecurity posture with our expert guidance and support.

 

References

Solution Advice
  1. Update bloofoxCMS to the latest version immediately to mitigate the SQL Injection vulnerability.
  2. Implement robust input validation and sanitization measures to prevent SQL Injection attacks.
  3. Regularly review and update security policies and practices to address potential vulnerabilities.
  4. Limit administrative access to trusted users and enforce strong password policies.
  5. Conduct regular security audits and penetration testing to identify and address vulnerabilities.
  6. Educate staff and users on security best practices to foster a culture of cybersecurity awareness.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-34752 scanner - SQL Injection vulnerability in bloofoxCMS | S4E