An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentication & Authorization component
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
http://biotime.com | broken link |
http://zkteko.com | permissions required |
https://gist.github.com/ipxsec/1680d29c49fe368be81b037168175b10 | third party advisory exploit |