CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2023-34752

Critical · CVSS 9.8

bloofox CMS — SQL Injection

CVSS
9.8
nvd
EPSS
KEV
No
Class
kernel local
CWE-89, CWE-89

Description

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

Search profile — drives PoC discovery

Symbols lidadmin/index.phpmode=settingspage=langaction=edit
Keywords CVE-2023-34752bloofoxbloofox CMS SQL injectionbloofox v0.5.2.1lid parameter SQL injectionbloofox admin SQL injection
Versions: v0.5.2.1

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z