CVE-2023-38950
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
- Affected products
- Zkteco Biotime
- Zkteco Biotime
- < 9.0.1
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 84.7% (100th percentile)
- Weakness
- CWE-22
- NVD status
- Analyzed
- Published
- 2023-08-03
CVE-2023-38950 at NVD
2 known exploits for CVE-2023-38950
Proof-of-concept code and exploit modules indexed by Sploitus