9.8
CVSSv3

CVE-2023-38951

Published: 03/08/2023 Updated: 08/08/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A path traversal vulnerability in ZKTeco BioTime v8.5.5 allows malicious users to write arbitrary files via using a malicious SFTP configuration.

Vulnerable Product Search on Vulmon Subscribe to Product

zkteco biotime 8.5.5

Exploits

BioTime versions 855 and 901 suffer from directory traversal and file write vulnerabilities This exploit also achieves remote code execution on version 855 ...