1 results (0.012 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do. Se ha detectado que ZKteco ZKBioSecurity V5000 versión 4.1.3, contiene una vulnerabilidad de inyección SQL por medio del componente /baseOpLog.do ZKSecurity BIO version 4.1.2 suffers from a remote SQL injection vulnerability that can allow for remote code execution. • http://zkbiosecurity.com http://zkteco.com https://medium.com/stolabs/cve-2022-36635-a-sql-injection-in-zksecuritybio-to-rce-c5bde2962d47 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •