CVE-2023-54163
8.2NLB Banka AD Skopje · NLB mKlik Makedonija
NLB mKlik Makedonija version 3.3.12 contains a SQL injection vulnerability in international transfer parameters allowing unauthenticated attackers to manipulate database queries and disclose information.
Executive summary
A critical SQL injection vulnerability in NLB mKlik Makedonija allows unauthenticated attackers to compromise sensitive database information via manipulated international transfer parameters.
Vulnerability
The application is susceptible to a SQL injection flaw (CWE-89) within the international transfer functionality. Unauthenticated attackers can inject arbitrary SQL commands into the input parameters to bypass security controls and extract data from the backend database.
Business impact
Successful exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive financial and personal user information stored within the mobile banking application. Given the CVSS score of 8.2, this represents a high severity risk that could result in significant reputational damage, regulatory non-compliance, and loss of customer trust.
Remediation
Immediate Action: Since a specific patch version is not currently identified, users should contact the vendor immediately for guidance on available security updates or service patches.
Proactive Monitoring: Security teams should monitor application access logs for unusual SQL syntax or unexpected character patterns in international transfer requests.
Compensating Controls: Deploy a Web Application Firewall (WAF) with strict SQL injection protection rules to inspect and block malicious payloads targeted at the international transfer API endpoints.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the Packet Storm Security reference.
Analyst recommendation
The presence of a public proof-of-concept combined with the lack of authentication requirements elevates the risk associated with this vulnerability. Organizations utilizing the NLB mKlik Makedonija application should prioritize engagement with the vendor to secure their environment and implement robust WAF filtering to mitigate the risk of exploitation while awaiting a permanent fix.
Sources
Originally found and disclosed by Neurogenesia, per the CVE Program record.
- Zero Science Lab Disclosure (ZSL-2023-5797) Third-party advisory
- Google Play Store App Listing
- Packet Storm Security Exploit Entry Exploit / PoC
- CXSecurity Vulnerability Listing Third-party advisory
- VulnCheck Advisory: NLB mKlik Macedonia 3.3.12 SQL Injection via International Transfer Parameters Third-party advisory