4.3
CVSSv2

CVE-2017-17057

Published: 04/12/2017 Updated: 21/12/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

There is a reflected XSS vulnerability in ZKTime Web 2.0.1.12280. The vulnerability exists due to insufficient filtration of user-supplied data in the 'Range' field of the 'Department' module in a Personnel Advanced Query. A remote attacker can execute arbitrary HTML and script code in the browser in the context of the vulnerable application.

Vulnerable Product Search on Vulmon Subscribe to Product

zkteco zktime web 2.0.1.12280

Exploits

ZKTeco ZKTime Web version 20112280 suffers from a cross site scripting vulnerability ...