References https://nvd.nist.gov/vuln/detail/CVE-2023-38950 https://claroty.com/team82/disclosure-dashboard/cve-2023-38950 https://avd.aliyun.com/detail?id=AVD-2023-38950 https://ddpoc.com/DVB-2025-10040.html https://cve.imfht.com/detail/CVE-2023-38950 https://pentest-tools.com/vulnerabilities-exploits/zkteco-biotime-v855-path-traversal_27171 https://www.zkteco.com/en/Security_Bulletinsibs/10 https://www.tenable.com/cve/CVE-2023-38950 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-38950.yaml https://www.cve.org/CVERecord?id=CVE-2023-38950
Related VulnerabilitiesZKTeco BioTime 平台 /accounts/login 默认口令漏洞用友政务财务云A++ V8 /lp/gwzjConfig/getTableColumn SQL 注入漏洞关于用友财务云A++V8系列产品接口(/XXX/getTableColumn)存在SQL注入安全漏洞的公告关于用友财务云A++V8系列产品(ma)系列接口敏感信息泄露、SQL注入以及(/A/XXXX/ssoLogin)接口SQL注入安全漏洞的公告关于用友财务云A++V8系列产品接口(/XXX/selectMaEmp)未授权访问及逻辑缺陷安全漏洞的公告PoC用友Bip /bi/api/Portal/LoginWithV8 目录遍历漏洞(CVE-2025-66744)PoCCVE-2023-38952: ZKTeco BioTime <= 9.0.1 - Privilege Escalation关于用友A++V8系列产品gl/XXX/searchVou及/ma/XXX/taxPay及/ma/XXX/pageMaEmpProperty接口SQL注入漏洞的安全公告用友BIP LoginWithV8 登录绕过漏洞ZKTeco ZKBio CVSecurity /app/v1/photoBase64 目录遍历漏洞(CVE-2024-35431)PoC用友BIP数据应用服务 /bi/api/Portal/LoginWithV8 信息泄露漏洞