CVE-2023-38954: SQL Injection
Published Aug 3, 2023
·Updated
ZKTeco BioAccess IVS v3.3.1 was discovered to contain a SQL injection vulnerability.
Affected Software
1 affected component
ZKTeco BioAccess IVS=3.3.1
Event History
Aug 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
02:15 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-38954?
CVE-2023-38954 is a SQL injection vulnerability in ZKTeco BioAccess IVS v3.3.1.
2
How severe is CVE-2023-38954?
CVE-2023-38954 has a severity rating of critical (9.8 out of 10).
3
What software is affected by CVE-2023-38954?
ZKTeco BioAccess IVS v3.3.1 is affected by CVE-2023-38954.
4
How can I fix CVE-2023-38954?
To fix CVE-2023-38954, it is recommended to update ZKTeco BioAccess IVS to a version that includes a patch for the vulnerability.
5
What is the CWE ID for CVE-2023-38954?
The CWE ID for CVE-2023-38954 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).