Skip to content

Latest commit

 

History

History
8 lines (6 loc) · 505 Bytes

CVE-2024-35433.md

File metadata and controls

8 lines (6 loc) · 505 Bytes

CVE-2024-35433

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create a new admin user.

Poc

Send the following request as an authenticated user.A copy is available here Don't forget to update cookies.

image