CVE-2023-26443 Information
Aug 03, 2023
cve
Description
Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place this can be abused to trigger benign SQL Exceptions but could potentially be escalated to a malicious SQL injection vulnerability. We now properly encode single quotes for SQL FULLTEXT queries. No publicly available exploits are known.
Reference
https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6230_7.10.6_2023-05-02.pdf http://seclists.org/fulldisclosure/2023/Aug/8
Share on: