CVE-2023-48050: SQL Injection
SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the controllers/controllers.py component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48050?
CVE-2023-48050 has a high severity rating due to its potential for remote code execution and privilege escalation.
How do I fix CVE-2023-48050?
To fix CVE-2023-48050, update the Cams Biometrics Integration Module or Odoo Biometric Attendance to the latest version that addresses this vulnerability.
What software versions are affected by CVE-2023-48050?
CVE-2023-48050 affects versions 13.0 to 16.0.1 of both Cams Biometrics Zkteco, eSSL, and Odoo Biometric Attendance.
Who can exploit CVE-2023-48050?
A remote attacker can exploit CVE-2023-48050 using SQL injection on the vulnerable software.
What vulnerabilities does CVE-2023-48050 allow an attacker to exploit?
CVE-2023-48050 allows an attacker to execute arbitrary code and gain elevated privileges via manipulated input.