PT-2024-18239 · Zkteco · Zkbio Access Ivs

Hussein Amer

·

Published

2024-02-21

·

Updated

2024-05-17

·

CVE-2024-1706

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ZKTeco ZKBio Access IVS versions up to 3.3.2
Description A problematic issue has been found in the Department Name Search Bar component, allowing for cross-site scripting through the manipulation of input, such as <marquee>hi. This can be exploited remotely. The issue has been publicly disclosed.
Recommendations For ZKTeco ZKBio Access IVS versions up to 3.3.2, consider restricting access to the Department Name Search Bar component until a fix is available. As a temporary workaround, avoid using the input field in the Department Name Search Bar to minimize the risk of exploitation.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-1706

Affected Products

Zkbio Access Ivs