---
id: CVE-2023-54163
title: >-
  NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in
  international transfer parameters that allows attackers to manipulate database
  queries
summary: >-
  NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in
  international transfer parameters that allows attackers to manipulate database
  queries. Attackers can inject arbitrary SQL code through unsanitized input to
  potentially…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-89
vendor: nlb
product: mklik_makedonija
affected:
  - mklik_makedonija = 3.3.12
published: '2025-12-30'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T23:10:00.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-54163'
references:
  - url: 'https://cxsecurity.com/issue/WLB-2023100040'
    label: disclosure@vulncheck.com
  - url: >-
      https://packetstormsecurity.com/files/175113/NLB-mKlik-Makedonija-3.3.12-SQL-Injection.html
    label: disclosure@vulncheck.com
  - url: >-
      https://play.google.com/store/apps/details?id=hr.asseco.android.jimba.tutunskamk.production
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nlb-mklik-macedonia-sql-injection-via-international-transfer-parameters
    label: disclosure@vulncheck.com
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5797.php'
    label: disclosure@vulncheck.com
  - url: 'https://cxsecurity.com/issue/WLB-2023100040'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5797.php'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00343
epssPercentile: 0.25102
ingestedAt: '2026-09-24T23:55:20.489Z'
---

## Overview

NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through unsanitized input to potentially disclose sensitive information from the mobile banking application.

## Affected

- `mklik_makedonija = 3.3.12`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
