Skip to content

Instantly share code, notes, and snippets.

View ipxsec's full-sized avatar

Abdulwahab ipxsec

  • Freelancer
  • Saudi Arabia
  • X @ipxsec
View GitHub Profile

User Enumeration

Description:

An issue in ZKTeco BioTime v.8.5.4 allows a remote attacker to obtain sensitive information.

Impact

An attacker can perform a brute-force attack with common usernames, or may use census data of common last names and append each letter of the alphabet to generate valid username lists.

Vulnerability path:

@ipxsec
ipxsec / CVE-2023-51141.md
Last active February 28, 2024 08:13
CVE-2023-51141

Information Disclosure - Internal Users

Description:

ZKTeko BioTime v.8.5.4 contains an affected endpoint that discloses employees data (name, employment ID, photo, etc) which can be accessed without authentication and authorization checks.

Impact

An attacker might use the disclosed information to gain a greater understanding of the systems and the employees and potentially develop further attacks targeted at the organization e.g. the attacker might use the employees usernames and IDs to gain access to different employees-only systems. Also, The attacker can leak those information to the internet.

Vulnerability path: