LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2016-20029

Published
CVSS6.2
Severitymedium
WeaknessCWE-276
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used to retrieve local resources. Attackers can manipulate path parameters to bypass access controls and retrieve sensitive information including configuration files, source code, and protected application resources.

References

← Back to the CVE Tracker

Our coverage of CVE-2016-20029

No stories yet. This page updates automatically when we publish reporting that references CVE-2016-20029.