CVE-2017-13129: CSRF
Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrators for requests that add administrators by leveraging lack of anti-CSRF tokens.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13129?
CVE-2017-13129 is classified as a high severity cross-site request forgery (CSRF) vulnerability.
How does CVE-2017-13129 affect ZKTeco ZKTime Web?
CVE-2017-13129 allows remote authenticated users to hijack the authentication of administrators due to the lack of anti-CSRF tokens.
Who is affected by CVE-2017-13129?
CVE-2017-13129 affects remote authenticated users of ZKTeco ZKTime Web version 2.0.1.12280.
How can I fix CVE-2017-13129?
To fix CVE-2017-13129, implement anti-CSRF tokens in the application to protect against CSRF attacks.
Is there a patch available for CVE-2017-13129?
As of the information available, there is no specific patch announced for CVE-2017-13129, and users are advised to secure their applications through coding practices.