Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-50429: IzyBat Orange casiers - SQL injection

IzyBat Orange casiers before 20230803_1 allows getEnsemble.php ensemble SQL injection.

CVE
#sql#vulnerability#web#mac#php

Overview

Possible SQL injection from the web portal https://orange-casiers.fr/

Details

SQL injection makes it possible to retrieve the RFID of employees in the database, which allows them to emulate their badge (e.g. with a zero pinball machine) and open their locker(s). In addition, SQLi allows you to recover the entire database (email, password hashes, etc.).
The vulnerability concerns the getEnsemble.php endpoint on a POST request and it is the ensemble parameter which is vulnerable. See PoC_1

Proof of Concept

See PoC_2, PoC_3, PoC_4

References****Credits

Arthur NAULLET at Orange group

Orange CERT-CC at Orange group

Timeline

Date reported: August 2, 2023
Date fixed: August 3, 2023

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907