CVE-2024-11049

LOW

ZKTeco ZKBio Time 9.0.1 - Direct Request in Image File Handler

Title source: llm
STIX 2.1

Description

A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1. Affected is an unknown function of the file /auth_files/photo/ of the component Image File Handler. The manipulation leads to direct request. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required vdb-entry technical-description
https://vuldb.com/?id.283662
Permissions Required signature permissions-required
https://vuldb.com/?ctiid.283662
Third Party Advisory third-party-advisory
https://vuldb.com/?submit.435034

Scores

CVSS v3 3.7
EPSS 0.0042
EPSS Percentile 33.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-425
Status published
Products (1)
zkteco/zkbio_time 9.0.1
Published Nov 10, 2024
Tracked Since Feb 18, 2026