ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server which can lead to DoS.
References
Configurations
History
No history.
Information
Published : 2024-05-30 17:15
Updated : 2025-03-13 15:15
NVD link : CVE-2024-35428
Mitre link : CVE-2024-35428
CVE.ORG link : CVE-2024-35428
JSON object : View
Products Affected
zkteco
- zkbio_cvsecurity
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')