CVE-2023-38950
03.08.2023, 23:15
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
| Vendor | Product | Version |
|---|---|---|
| zkteco | biotime | 𝑥 < 9.0.1 |
𝑥
= Vulnerable software versions
References