CVE-2024-24257: ZKTeco Zktime Web

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information via a crafted script to the csl/user component.

Affected products

  • ZKTeco Zktime Web: version 3.0 only

Published 2024-07-26. Last modified 2026-06-17.