CVE-2016-20032
ZKTeco ZKAccess Security System 5.3.1 Stored XSS
ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads through the 'holiday_name' and 'memo' POST parameters. Attackers can submit crafted requests with script code in these parameters to compromise user browser sessions and steal sensitive information.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Productos afectados
ZKTeco Inc. · ZKTeco ZKAccess Security System¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://cxsecurity.com/issue/WLB-2016090004https://exchange.xforce.ibmcloud.com/vulnerabilities/116479https://packetstormsecurity.com/files/138572https://www.exploit-db.com/exploits/40328/https://www.vulncheck.com/advisories/zkteco-zkaccess-security-system-stored-xsshttps://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5368.php