CVE-2017-13129: ZKTeco Zktime Web

High severity, CVSS 8.0. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrators for requests that add administrators by leveraging lack of anti-CSRF tokens.

Affected products

  • ZKTeco Zktime Web: version 2.0.1.12280 only

Published 2017-09-26. Last modified 2026-06-17.