CVE-2023-46348: Sunnytoo Sturls
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and StUrls::getInstanceId methods.
Affected products
- Sunnytoo Sturls: before 1.1.13 (fixed in 1.1.13)
Published 2023-12-14. Last modified 2026-06-17.