CVE-2024-2318: ZKTeco ZKBio Media Service Port 9999 download path traversal
A vulnerability was found in ZKTeco ZKBio Media 2.0.0x642024-01-29-1028. It has been classified as problematic. Affected is an unknown function of the file /pro/common/download of the component Service Port 9999. The manipulation of the argument fileName with the input ../../../../zkbiomedia.sql leads to path traversal: '../filedir'. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.1.3 Build 2025-05-26-1605 is able to address this issue. It is recommended to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2318?
CVE-2024-2318 has been classified as problematic due to its potential impact on the system.
How do I fix CVE-2024-2318?
To fix CVE-2024-2318, it's recommended to update ZKTeco ZKBio Media to the latest version provided by the vendor.
What component is affected by CVE-2024-2318?
CVE-2024-2318 affects the Service Port 9999 in the ZKTeco ZKBio Media application.
What type of vulnerability is CVE-2024-2318?
CVE-2024-2318 is a path traversal vulnerability that allows manipulation of the argument fileName.
Where is the affected function located in CVE-2024-2318?
The affected function related to CVE-2024-2318 is located in the file /pro/common/download.