CVE-2024-22988: Code Injection
Published Feb 23, 2024
·Updated
ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp.
Affected Software
2 affected components
ZKTeco ZKBio WDMS=8.0.5
ZKTeco ZKBio WDMS=8.0.5
Event History
Feb 23, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-22988?
CVE-2024-22988 is considered a critical vulnerability due to its ability to allow arbitrary code execution.
2
How can I mitigate CVE-2024-22988?
To mitigate CVE-2024-22988, it is recommended to upgrade ZKTeco ZKBio WDMS to a version later than 8.0.5.
3
What components are affected by CVE-2024-22988?
CVE-2024-22988 affects the /files/backup/ component in ZKTeco ZKBio WDMS version 8.0.5.
4
Who is affected by CVE-2024-22988?
Organizations and users utilizing ZKTeco ZKBio WDMS version 8.0.5 are at risk due to CVE-2024-22988.
5
What types of attacks can CVE-2024-22988 enable?
CVE-2024-22988 can enable attackers to execute arbitrary code on vulnerable systems.