CVE-2017-17057
ZKTeco ZKTime Web 2.0.1.12280 Cross Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
There is a reflected XSS vulnerability in ZKTime Web 2.0.1.12280. The vulnerability exists due to insufficient filtration of user-supplied data in the 'Range' field of the 'Department' module in a Personnel Advanced Query. A remote attacker can execute arbitrary HTML and script code in the browser in the context of the vulnerable application.
Hay una vulnerabilidad de XSS reflejado en ZKTime Web 2.0.1.12280. La vulnerabilidad existe debido a la filtración insuficiente de datos proporcionados por el usuario en el campo "Range" del módulo "Department" en una consulta Personnel Advanced Query. Un atacante remoto puede ejecutar scripts y código HTML arbitrarios en el navegador en el contexto de la aplicación vulnerable.
ZKTeco ZKTime Web version 2.0.1.12280 suffers from a cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-11-29 CVE Reserved
- 2017-11-30 CVE Published
- 2023-10-14 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/102006 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
http://packetstormsecurity.com/files/145159/ZKTeco-ZKTime-Web-2.0.1.12280-Cross-Site-Scripting.html | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zkteco Search vendor "Zkteco" | Zktime Web Search vendor "Zkteco" for product "Zktime Web" | 2.0.1.12280 Search vendor "Zkteco" for product "Zktime Web" and version "2.0.1.12280" | - |
Affected
|