CVE-2022-36635: SQL Injection
Published Oct 7, 2022
·Updated
ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.
Affected Software
1 affected component
ZKTeco ZKBioSecurity V5000=4.1.3
Event History
Oct 7, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-36635?
CVE-2022-36635 is a SQL injection vulnerability found in ZKteco ZKBioSecurity V5000 4.1.3, specifically in the component /baseOpLog.do.
2
How severe is CVE-2022-36635?
CVE-2022-36635 has a severity score of 8.8 out of 10, which is considered high.
3
How does CVE-2022-36635 affect ZKteco ZKBioSecurity V5000?
CVE-2022-36635 affects ZKteco ZKBioSecurity V5000 version 4.1.3.
4
How can I fix CVE-2022-36635?
To fix CVE-2022-36635, it is recommended to apply the latest security patch or update provided by ZKteco.
5
What is the CWE classification for CVE-2022-36635?
CVE-2022-36635 is classified under CWE-89, which is related to SQL injection vulnerabilities.