Sploitus

CVE-2024-11049

No indexed exploits for CVE-2024-11049 yet

A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1. Affected is an unknown function of the file /auth_files/photo/ of the component Image File Handler. The manipulation leads to direct request. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products
Zkteco Biotime
Zkteco Zkbio Time
= 9.0.1
CVSS 4.0
6.3 MEDIUM
CVSS 3.1
3.7 LOW
EPSS
0.4% (36th percentile)
Weakness
CWE-425
NVD status
Analyzed
Published
2024-11-10
CVE-2024-11049 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-11049 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-11049 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.