← Back to browse · API

CVE-2023-38950

Severity
HIGH
CVSS
7.5
EPSS
0.84702
Risk score
84.65
CISA KEV
Yes
PoC
No
Published
2025-05-19
Modified
2025-05-19
First seen
2026-08-07
Aliases
EUVD-2023-42710, GHSA-27MV-5VPC-8G53
Products
ZKTeco:BioTime, n/a:n/a n/a
Sources
euvd EUVD-2023-42710
cisa.gov CVE-2023-38950

Description

ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload.

References