CVE-2023-38950
biotime
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
- CVSS
- 7.5
- EPSS
- 84.7% 99.7% percentile
- CISA KEV
- Listed
- Published
- 2023.08.04