cvedb.io
CVE-2023-33179
MEDIUM · CVSS 6.5
EPSS exploitation probability: 0%
Published 2023-05-30T21:15:09.077 · Last modified 2026-06-17T06:01:14.750

Summary

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered starting in version 3.2.0 and prior to version 3.3.5 in the `nameFilter` function used throughout the CMS. This allows an authenticated user to exfiltrate data from the Xibo database by injecting specially crafted values for logical operators. Users should upgrade to version 3.3.5 which fixes this issue. There are no known workarounds aside from upgrading.

Affected products

xibosignage — xibo

Does this affect you?

Add your gear to cvedb and we'll alert you only when xibosignage ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.