Description
A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update LXCA to version 4.0 or later.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-38495 | A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API. |
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-98715 |
|
History
Tue, 03 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-12-03T18:31:42.016Z
Reserved: 2023-06-05T19:15:31.604Z
Link: CVE-2023-34418
Updated: 2024-08-02T16:10:06.834Z
Status : Modified
Published: 2023-06-26T20:15:10.183
Modified: 2024-11-21T08:07:11.870
Link: CVE-2023-34418
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD