CVE-2023-54163

8.2

NLB Banka AD Skopje · NLB mKlik Makedonija

NLB mKlik Makedonija version 3.3.12 contains a SQL injection vulnerability in international transfer parameters allowing unauthenticated attackers to manipulate database queries and disclose information.

Executive summary

A critical SQL injection vulnerability in NLB mKlik Makedonija allows unauthenticated attackers to compromise sensitive database information via manipulated international transfer parameters.

Vulnerability

The application is susceptible to a SQL injection flaw (CWE-89) within the international transfer functionality. Unauthenticated attackers can inject arbitrary SQL commands into the input parameters to bypass security controls and extract data from the backend database.

Business impact

Successful exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive financial and personal user information stored within the mobile banking application. Given the CVSS score of 8.2, this represents a high severity risk that could result in significant reputational damage, regulatory non-compliance, and loss of customer trust.

Remediation

Immediate Action: Since a specific patch version is not currently identified, users should contact the vendor immediately for guidance on available security updates or service patches.

Proactive Monitoring: Security teams should monitor application access logs for unusual SQL syntax or unexpected character patterns in international transfer requests.

Compensating Controls: Deploy a Web Application Firewall (WAF) with strict SQL injection protection rules to inspect and block malicious payloads targeted at the international transfer API endpoints.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the Packet Storm Security reference.

Analyst recommendation

The presence of a public proof-of-concept combined with the lack of authentication requirements elevates the risk associated with this vulnerability. Organizations utilizing the NLB mKlik Makedonija application should prioritize engagement with the vendor to secure their environment and implement robust WAF filtering to mitigate the risk of exploitation while awaiting a permanent fix.

Sources

Originally found and disclosed by Neurogenesia, per the CVE Program record.