CVE-2023-45674 HIGH

CVE-2023-45674: SQL injection vulnerability in Farmbot-Web-App

Vendor Farmbot
Product Farmbot-Web-App
Weakness CWE-89 · SQLi
Published October 13, 2023
Last update September 16, 2024

CVSS base score

7.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

Farmbot-Web-App is a web control interface for the Farmbot farm automation platform. An SQL injection vulnerability was found in FarmBot's web app that allows authenticated attackers to extract arbitrary data from its database (including the user table). This issue may lead to Information Disclosure. This issue has been patched in version 15.8.4. Users are advised to upgrade. There are no known workarounds for this issue.

Key dates

02Disclosure timeline

October 13, 2023 CVE published
September 16, 2024 Record updated