ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server which can lead to DoS.
References
Configurations
History
21 Nov 2024, 09:20
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/mrojz/ZKT-Bio-CVSecurity/blob/main/CVE-2024-35428.md - Exploit |
18 Jul 2024, 16:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/mrojz/ZKT-Bio-CVSecurity/blob/main/CVE-2024-35428.md - Exploit | |
Summary |
|
|
CPE | cpe:2.3:a:zkteco:zkbio_cvsecurity:6.1.1:*:*:*:*:*:*:* | |
First Time |
Zkteco
Zkteco zkbio Cvsecurity |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
CWE | CWE-22 |
30 May 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-30 17:15
Updated : 2024-11-21 09:20
NVD link : CVE-2024-35428
Mitre link : CVE-2024-35428
CVE.ORG link : CVE-2024-35428
JSON object : View
Products Affected
zkteco
- zkbio_cvsecurity
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')