NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through unsanitized input to potentially disclose sensitive information from the mobile banking application.
References
| Link | Resource |
|---|---|
| https://cxsecurity.com/issue/WLB-2023100040 | Issue Tracking Third Party Advisory |
| https://packetstormsecurity.com/files/175113/NLB-mKlik-Makedonija-3.3.12-SQL-Injection.html | Third Party Advisory |
| https://play.google.com/store/apps/details?id=hr.asseco.android.jimba.tutunskamk.production | Product |
| https://www.vulncheck.com/advisories/nlb-mklik-macedonia-sql-injection-via-international-transfer-parameters | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5797.php | Third Party Advisory |
| https://cxsecurity.com/issue/WLB-2023100040 | Issue Tracking Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5797.php | Third Party Advisory |
Configurations
History
16 Jan 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://cxsecurity.com/issue/WLB-2023100040 - Issue Tracking, Third Party Advisory |
13 Jan 2026, 21:38
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:nlb:mklik_makedonija:3.3.12:*:*:*:*:android:*:* | |
| First Time |
Nlb
Nlb mklik Makedonija |
|
| References | () https://cxsecurity.com/issue/WLB-2023100040 - Third Party Advisory, Issue Tracking | |
| References | () https://packetstormsecurity.com/files/175113/NLB-mKlik-Makedonija-3.3.12-SQL-Injection.html - Third Party Advisory | |
| References | () https://play.google.com/store/apps/details?id=hr.asseco.android.jimba.tutunskamk.production - Product | |
| References | () https://www.vulncheck.com/advisories/nlb-mklik-macedonia-sql-injection-via-international-transfer-parameters - Third Party Advisory | |
| References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5797.php - Third Party Advisory |
02 Jan 2026, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://cxsecurity.com/issue/WLB-2023100040 - | |
| References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5797.php - |
30 Dec 2025, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-30 23:15
Updated : 2026-01-16 19:16
NVD link : CVE-2023-54163
Mitre link : CVE-2023-54163
CVE.ORG link : CVE-2023-54163
JSON object : View
Products Affected
nlb
- mklik_makedonija
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
