CVE-2023-5046: Biltay Procost

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Procost allows SQL Injection, Command Line Execution through SQL Injection. This issue affects Procost: before 1390.

Affected products

  • Biltay Procost: before 1390 (fixed in 1390)

Published 2023-10-12. Last modified 2026-06-17.