QID 730724
Date Published: 2023-02-13
QID 730724: ZFAKA SQL Command Vulnerability
ZFAKA is a free, safe, stable and efficient card issuance system.
Affected Versions:
ZFAKA v1.4.3 and earlier.
QID Detection logic:
This QID checks for the vulnerable versions of ZFAKA via querying 'product' endpoint.
an attacker can use to complete SQL injection in the foreground and add a background administrator account.
Solution
Update the product to ZFAKA v1.4.4 to fix the issue.
Vendor References
- CVE-2022-22294 -
github.com/zfaka-plus/zfaka/pull/237
CVEs related to QID 730724
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-22294 |
|