CVE-2024-24257: ZKTeco Zktime Web
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information via a crafted script to the csl/user component.
Affected products
- ZKTeco Zktime Web: version 3.0 only
Published 2024-07-26. Last modified 2026-06-17.