CVE-2023-27167 | Suprema BioStar 2 2.8.16 absence values sql injection (ID 171523 / EDB-51340)
A vulnerability was found in Suprema BioStar 2 2.8.16. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /users/absence?search_month=1. The manipulation of the argument values leads to sql injection.
This vulnerability is known as CVE-2023-27167. The attack needs to be initiated within the local network. Furthermore, there is an exploit available.