ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them through filename enumeration.
                
            References
                    | Link | Resource | 
|---|---|
| https://codingkoala.eu/posts/CVE202230515/ | Exploit Third Party Advisory | 
| https://www.zkteco.me/software-5 | Product Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2022-11-08 23:15
Updated : 2022-11-09 16:32
NVD link : CVE-2022-30515
Mitre link : CVE-2022-30515
CVE.ORG link : CVE-2022-30515
JSON object : View
Products Affected
                zkteco
- biotime
CWE
                
                    
                        
                        CWE-306
                        
            Missing Authentication for Critical Function
