Home

Description

NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through unsanitized input to potentially disclose sensitive information from the mobile banking application.

PUBLISHED Reserved 2025-12-26 | Published 2025-12-30 | Updated 2025-12-30 | Assigner VulnCheck




HIGH: 8.8CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
HIGH: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Problem types

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

3.3.12
affected

Credits

Neurogenesia finder

References

www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5797.php (Zero Science Lab Disclosure (ZSL-2023-5797)) third-party-advisory

play.google.com/...sseco.android.jimba.tutunskamk.production (Google Play Store App Listing) product

packetstormsecurity.com/...edonija-3.3.12-SQL-Injection.html (Packet Storm Security Exploit Entry) exploit

cxsecurity.com/issue/WLB-2023100040 (CXSecurity Vulnerability Listing) third-party-advisory

www.vulncheck.com/...n-via-international-transfer-parameters (VulnCheck Advisory: NLB mKlik Macedonia 3.3.12 SQL Injection via International Transfer Parameters) third-party-advisory

cve.org (CVE-2023-54163)

nvd.nist.gov (CVE-2023-54163)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.