CVE-2023-26443
Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitizati
Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abused to trigger benign SQL Exceptions but could potentially be escalated to a malicious SQL injection vulnerability. We now properly encode single quotes for SQL FULLTEXT queries.
No publicly available exploits are known.
MEDIUM · CVSS 5.5
EPSS 0.00062
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0