CVE-2023-49954 is a critical SQL Injection vulnerability affecting the CRM Integration in 3CX versions before 18.0.9.23 and 20 before 20.0.0.1494. This flaw allows unauthenticated attackers to inject malicious SQL queries through fields like first name, search string, or email address. With a CVSS score of 9.8, it presents a severe risk, enabling full compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, the vulnerability has garnered significant community discussion and media attention, indicating a high level of awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.0.9.23CPE matchmatch criteria | cpe:2.3:a:3cx:3cx:*:*:*:*:*:*:*:* | ||
>= 20.0, < 20.0.0.1494CPE matchmatch criteria | cpe:2.3:a:3cx:3cx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.