External risk intelligence

Kayisi software lets attackers take control of systems and steal sensitive files

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2023-5045

An external attacker can exploit a flaw in Biltay Technology Kayisi to run unauthorized commands. This could allow them to gain complete administrative control of the hosting server, steal sensitive files, and potentially compromise other systems on our network.

2Halo Surface Signal

SQL Injection

Biltay Kayisi

before 1286

External exposure likelihood

Halo Surface Signal score for CVE-2023-5045

Kayisi is an enterprise Quality and Document Management System (QDMS) used for internal quality assurance, audits, and ISO compliance. In typical deployments, these systems are hosted internally on corporate networks or behind VPNs and internal access controls rather than being directly exposed to the public internet.

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability in Biltay Technology Kayisi allows unauthorized access to your database, potentially enabling attackers to execute commands on your system. This could lead to significant data compromise or disruption of services.

  • Database compromise
  • System command execution
  • Data loss or theft

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this SQL Injection vulnerability by sending specially crafted input to the vulnerable application. This allows them to manipulate database queries, potentially leading to unauthorized data access, modification, or even command execution on the underlying server.

  • No authentication required.
  • Targets SQL database queries.
  • Can lead to server command execution.

Live Threat

Current exploitation, exposure, and threat context

This SQL injection vulnerability offers attackers significant control, allowing for command line execution. Such a potent combination of impacts makes it a prime candidate for weaponization, especially since it affects systems accessible remotely with no authentication required. The lack of public exploit code or KEV listing suggests a potential delay in widespread exploitation, but this could change rapidly if details emerge.

  • SQL injection with RCE is highly desirable.
  • No public exploit or KEV listing.
  • Critical impact, no auth required.

Priority actions

Operational Fix

Recommended remediation, mitigation, and detection steps

Prioritize blocking malicious traffic targeting the SQL injection vulnerability in Kayisi, as unauthenticated remote attackers can execute commands. If the vulnerability is actively exploited, consider taking affected Kayisi services offline or isolating them until a patch is applied.

  • Upgrade Kayisi to version 1286 or later.
  • Monitor logs for suspicious SQL queries or command execution attempts.
  • Block network traffic from untrusted sources to Kayisi.

Frequently asked questions

What is Biltay Technology Kayisi and what is it used for?

Biltay Technology Kayisi is a Quality and Document Management System (QDMS) used by businesses for internal quality assurance processes, audits, and ensuring ISO compliance. It helps organizations manage their quality-related documentation and workflows.

What is CVE-2023-5045 and how does it affect Kayisi software?

CVE-2023-5045 is an SQL Injection vulnerability in Biltay Technology Kayisi. This weakness allows attackers to manipulate database queries, potentially leading to the execution of commands on the underlying server and unauthorized access to sensitive data.

How can an attacker exploit this SQL Injection vulnerability in Kayisi?

An unauthenticated attacker can exploit this vulnerability by sending specially crafted input to the Kayisi application. This input is designed to trick the SQL database into executing unintended commands, which can result in data compromise or server command execution without any user authentication.

Who should be concerned about the CVE-2023-5045 vulnerability in Kayisi?

Organizations using Biltay Technology Kayisi should be concerned. While typically deployed internally, if any instance is accessible from the internet, it presents a significant risk due to the potential for remote exploitation.

What are the first steps for responding to this Kayisi vulnerability?

The immediate priority is to upgrade Biltay Technology Kayisi to version 1286 or later. Additionally, monitor system logs for any signs of suspicious SQL queries or command execution attempts and consider isolating affected systems if immediate patching is not possible.

References