CVE-2023-45800
Status: ModifiedHigh (7.5)—
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hanbiro Hanbiro groupware allows Information Elicitation.This issue affects Hanbiro groupware: from V3.8.79 before V3.8.81.1.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.61%
- Percentile among all scored CVEs: 47
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-89
- CWE-89
References
Raw JSON (NVD)
Show
{
"id": "CVE-2023-45800",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "vuln@krcert.or.kr",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "vuln@krcert.or.kr",
"affectedData": [
{
"vendor": "Hanbiro",
"product": "Hanbiro groupware",
"versions": [
{
"status": "affected",
"version": "V3.8.79",
"lessThan": "V3.8.81.1",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-12-13T02:15:07.323",
"references": [
{
"url": "https://hanbiro.com/",
"tags": [
"Product"
],
"source": "vuln@krcert.or.kr"
},
{
"url": "https://hanbiro.com/",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "vuln@krcert.or.kr",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hanbiro Hanbiro groupware allows Information Elicitation.This issue affects Hanbiro groupware: from V3.8.79 before V3.8.81.1.\n\n"
},
{
"lang": "es",
"value": "La neutralización inadecuada de elementos especiales utilizados en una vulnerabilidad de comando SQL ('inyección SQL') en el software colaborativo Hanbiro Hanbiro permite la obtención de información. Este problema afecta al software colaborativo Hanbiro: desde V3.8.79 antes de V3.8.81.1."
}
],
"lastModified": "2026-06-17T06:29:32.790",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hanbiro:groupware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A78D52F3-B19F-4BBD-9EE1-613EF89C79F0",
"versionEndExcluding": "3.8.81.1",
"versionStartIncluding": "3.8.79"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vuln@krcert.or.kr"
}