ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://seclists.org/bugtraq/2017/Sep/20 | mailing list third party advisory exploit |
http://seclists.org/fulldisclosure/2017/Sep/39 | mailing list third party advisory exploit |