FixVibe

critical

SQL Injection in TMT Lockcell (CVE-2023-3047)

TMT Lockcell before version 15 is affected by CVE-2023-3047 SQL injection. FixVibe verified active scans flag Lockcell login pages that behave as the advisory describes.

CVE-2023-3047CWE-89

Attacker Impact

CVE-2023-3047 affects TMT Lockcell before version 15 and is scored critical by NVD [S1]. Public advisory sources describe unauthenticated SQL injection risk in the Lockcell login flow [S2][S3]. If an exposed deployment is affected, an attacker may bypass intended authentication or interact with backend database data, depending on deployment and privileges.

Root Cause

The issue is SQL injection caused by improper neutralization of user-supplied input before database query evaluation [S1]. Login input that changes SQL syntax can cross an authorization boundary when the affected Lockcell runtime is exposed.

Concrete Fixes

Upgrade TMT Lockcell to version 15 or newer [S1]. While rollout is in progress, restrict the Lockcell management UI to trusted networks, VPN, SSO, or an authenticated reverse proxy. Review authentication logs for unexpected activity, rotate credentials if unauthorized access is suspected, and verify normal invalid logins are denied after the patched runtime is deployed.

Covered by FixVibe

FixVibe's verified active scans flag TMT Lockcell login pages on your domain that show the SQL injection behavior described in this advisory, reported as a likely issue.