SecOpsNews / news

RSS items as GitHub Issues for the discerning engineering leader or security professional
MIT License
34 stars 0 forks source link

[FullDisclosure] ZKBiosecurity - Authenticated SQL Injection resulting in RCE (CVE-2022-36635) #3487

Closed github-actions[bot] closed 1 year ago

github-actions[bot] commented 1 year ago

Posted by Caio B on Sep 30

#######################ADVISORY INFORMATION#######################

Product: ZKSecurity BIO

Vendor: ZKTeco (

https://www.zkteco.com/en/ZKBiosecurity/ZKBioSecurity_V5000_4.1.2)

Version Affected: 4.1.2

CVE: CVE-2022-36635

Vulnerability: SQL Injection (with a plus: RCE)

#######################CREDIT#######################

This vulnerability was discovered and researched by Caio Burgardt and

Silton Santos....

https://seclists.org/fulldisclosure/2022/Sep/28

github-actions[bot] commented 1 year ago

This issue is stale because it has been open 1 day with no activity. Remove stale label or comment or this will be closed in 1 day.

github-actions[bot] commented 1 year ago

This issue was closed because it has been stale with no activity.