ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T03:14:53.145Z

Reserved:

Link: CVE-2024-35431

cve-icon Vulnrichment

Updated: 2024-08-02T03:14:53.145Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-30T17:15:34.277

Modified: 2024-08-01T13:52:41.087

Link: CVE-2024-35431

cve-icon Redhat

No data.