vendor:
ZKBioSecurity
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
CSRF
352
CWE
Product Name: ZKBioSecurity
Affected Version From: 3.0.1.0_R_230
Affected Version To: 3.0.1.0_R_230
Patch Exists: NO
Related CWE:
CPE: a:zkteco:zkbiosecurity:3.0.1.0_r_230
Platforms Tested: Microsoft Windows 7 Ultimate SP1 (EN), Microsoft Windows 7 Professional SP1 (EN), Apache-Coyote/1.1, Apache Tomcat/7.0.56
2016
ZKTeco ZKBioSecurity 3.0 CSRF Add Superadmin Exploit
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Mitigation:
Apply the latest patch or upgrade to a newer version of the software.