Lucene search

K
cvelistMitreCVELIST:CVE-2023-38952
HistoryAug 03, 2023 - 12:00 a.m.

CVE-2023-38952

2023-08-0300:00:00
mitre
www.cve.org
2
access control
zkteco biotime
unauthenticated attackers
sensitive information
http request
backup files
user credentials

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

58.6%

Insecure access control in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read sensitive backup files and access sensitive information such as user credentials via sending a crafted HTTP request to the static files resources of the system.

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

58.6%

Related for CVELIST:CVE-2023-38952