Unrated severityNVD Advisory· Published Jun 13, 2023· Updated Jan 3, 2025
benjjvi/PyBB may send unsanitized request to SQL database
CVE-2023-34249
Description
benjjvi/PyBB is an open source bulletin board. Prior to commit dcaeccd37198ecd3e41ea766d1099354b60d69c2, benjjvi/PyBB is vulnerable to SQL Injection. This vulnerability has been fixed as of commit dcaeccd37198ecd3e41ea766d1099354b60d69c2. As a workaround, a user may be able to update the software manually to avoid this problem by sanitizing user queries to BulletinDatabaseModule.py.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/benjjvi/PyBB/commit/dcaeccd37198ecd3e41ea766d1099354b60d69c2mitrex_refsource_MISC
- github.com/benjjvi/PyBB/security/advisories/GHSA-5qrx-fgxq-95ggmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.