CVE-2023-26443 Information

Description

Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place this can be abused to trigger benign SQL Exceptions but could potentially be escalated to a malicious SQL injection vulnerability. We now properly encode single quotes for SQL FULLTEXT queries. No publicly available exploits are known.

Reference

https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0003.json https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6230_7.10.6_2023-05-02.pdf http://seclists.org/fulldisclosure/2023/Aug/8

Share on: