CVE-2024-6344
- EPSS 0.1%
- Veröffentlicht 26.06.2024 11:15:52
- Zuletzt bearbeitet 10.07.2025 07:15:24
A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unknown part of the component Push Configuration Section. The manipulation of the argument Configuration Name leads to cross site ...
CVE-2024-6006
- EPSS 0.13%
- Veröffentlicht 15.06.2024 12:15:49
- Zuletzt bearbeitet 17.07.2025 06:15:24
A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Summer Schedule Handler. The manipulation of the argument Schedule Name leads to...
CVE-2024-6005
- EPSS 0.13%
- Veröffentlicht 15.06.2024 10:15:11
- Zuletzt bearbeitet 17.07.2025 06:15:21
A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Department Section. The manipulation of the argument Department Name le...
CVE-2022-36635
- EPSS 3.18%
- Veröffentlicht 07.10.2022 23:15:12
- Zuletzt bearbeitet 21.11.2024 07:13:26
ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do.
CVE-2022-36634
- EPSS 0.18%
- Veröffentlicht 07.10.2022 20:15:14
- Zuletzt bearbeitet 21.11.2024 07:13:26
An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a crafted HTTP request.