Byzoro · Byzoro S210 · CVE-2023-7039
**Name of the Vulnerable Software and Affected Versions**
Byzoro S210 up to 20231210
Beijing Baichuo S210 up to 20231210
**Description**
A critical issue has been discovered, affecting an unknown function of the file /importexport.php. The manipulation of the `sql` argument leads to injection. This issue can be exploited remotely.
**Recommendations**
For Byzoro S210 up to 20231210, consider restricting access to the /importexport.php file until a patch is available.
For Beijing Baichuo S210 up to 20231210, consider restricting access to the /importexport.php file until a patch is available.
As a temporary workaround, avoid using the `sql` argument in the affected file until the issue is resolved.