CVE-2024-35431

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1.
Configurations

No configuration.

History

15 May 2025, 22:15

Type Values Removed Values Added
Summary (en) ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. (en) ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1.

21 Nov 2024, 09:20

Type Values Removed Values Added
References () https://github.com/mrojz/ZKT-Bio-CVSecurity/blob/main/CVE-2024-35431.md - () https://github.com/mrojz/ZKT-Bio-CVSecurity/blob/main/CVE-2024-35431.md -

01 Aug 2024, 13:52

Type Values Removed Values Added
Summary
  • (es) ZKTeco ZKBio CVSecurity 6.1.1 es vulnerable a Directory Traversal a través de photoBase64. Un usuario no autenticado puede descargar archivos locales desde el servidor.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-31

30 May 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-30 17:15

Updated : 2025-05-15 22:15


NVD link : CVE-2024-35431

Mitre link : CVE-2024-35431

CVE.ORG link : CVE-2024-35431


JSON object : View

Products Affected

No product.

CWE
CWE-31

Path Traversal: 'dir\..\..\filename'