CVE-2023-34752
Critical · CVSS 9.8bloofox CMS — SQL Injection
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- kernel local
- CWE-89, CWE-89
Description
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.
Search profile — drives PoC discovery
Symbols lidadmin/index.phpmode=settingspage=langaction=edit
Keywords CVE-2023-34752bloofoxbloofox CMS SQL injectionbloofox v0.5.2.1lid parameter SQL injectionbloofox admin SQL injection
Versions: v0.5.2.1
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z