CVE-2023-30555 describes multiple SQL injection vulnerabilities within the Archery open-source SQL audit platform, specifically affecting the 'archerydms archery' product. An authenticated attacker can exploit these flaws in the 'explain' method of 'sql_optimize.py' by manipulating the 'db_name' parameter, allowing arbitrary queries against connected databases. The vulnerability carries a CVSS score of 6.5 (Medium), indicating a network-based attack with low attack complexity and requiring low privileges, but leading to high confidentiality impact without affecting integrity or availability. Its EPSS score is low, suggesting a low probability of exploitation. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, indicating a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.9.0CPE matchmatch criteria | cpe:2.3:a:archerydms:archery:1.9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.