NVD disclosure day

Published threat advisories for June 14, 2023

CVE advisoryCRITICAL

CVE-2023-34752

Bloofox CMS SQL Injection in Settings.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in bloofoxcms, a web content management system. This flaw, affecting the `lid` parameter in the language settings, could allow unauthenticated attackers to execute arbitrary SQL commands, potentially leading to unauthorized database access, data corruption, or system compromise if t

CVE advisoryKnown Exploit

CVE-2023-29357

Microsoft SharePoint Server Privilege Escalation Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Microsoft SharePoint Server has an elevation of privilege vulnerability that allows an attacker to gain administrator privileges using spoofed tokens. This could allow unauthorized administrative control over affected systems. Organizations using SharePoint Server face business risk from this vulnerability.

• CISA KEV