First published: Fri Dec 15 2023(Updated: )
SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the controllers/controllers.py component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Camsbiometrics Zkteco\, Essl\, Cams Biometrics Integration Module | >=13.0<=16.0.1 | |
Odoo Biometric Attendance | >=13.0<=16.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48050 has a high severity rating due to its potential for remote code execution and privilege escalation.
To fix CVE-2023-48050, update the Cams Biometrics Integration Module or Odoo Biometric Attendance to the latest version that addresses this vulnerability.
CVE-2023-48050 affects versions 13.0 to 16.0.1 of both Cams Biometrics Zkteco, eSSL, and Odoo Biometric Attendance.
A remote attacker can exploit CVE-2023-48050 using SQL injection on the vulnerable software.
CVE-2023-48050 allows an attacker to execute arbitrary code and gain elevated privileges via manipulated input.