cbcvebase.

Zkteco Zktime Web vulnerabilities

4 known vulnerabilities affecting zkteco/zktime_web.

Total CVEs
4
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2017-14680P3HIGHCVSS 7.5PoCv2.0.1.122802017-09-21
CVE-2017-14680 [HIGH] CWE-200 CVE-2017-14680: ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a di ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document.
nvd
CVE-2017-13129P3HIGHCVSS 8.0PoCv2.0.1.122802017-09-26
CVE-2017-13129 [HIGH] CWE-352 CVE-2017-13129: Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authe Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrators for requests that add administrators by leveraging lack of anti-CSRF tokens.
nvd
CVE-2017-17056P3HIGHCVSS 8.8v2.0.1.122802017-12-04
CVE-2017-17056 [HIGH] CWE-352 CVE-2017-17056: The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the applic The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function of the Modify Password component, reachable via the old_password, new_password1, and new_password2 parameters to the /accounts/password_change/ URI. An attacker takes advantage of this scenario and creates
nvd
CVE-2017-17057P4MEDIUMCVSS 6.1v2.0.1.122802017-12-04
CVE-2017-17057 [MEDIUM] CWE-79 CVE-2017-17057: There is a reflected XSS vulnerability in ZKTime Web 2.0.1.12280. The vulnerability exists due to in There is a reflected XSS vulnerability in ZKTime Web 2.0.1.12280. The vulnerability exists due to insufficient filtration of user-supplied data in the 'Range' field of the 'Department' module in a Personnel Advanced Query. A remote attacker can execute arbitrary HTML and script code in the browser in the context of the vulnerable application.
nvd
Zkteco Zktime Web vulnerabilities | cvebase