Skip to main content

Vendor/product archive

zkteco / zktime_web CVEs

Beta · best-effort

4 CVEs tagged to zkteco / zktime_web0 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2017-17057

Published Dec 4, 2017

There is a reflected XSS vulnerability in ZKTime Web 2.0.1.12280. The vulnerability exists due to insufficient filtration of user-supplied data in the 'Range' field of the 'Depart…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17056

Published Dec 4, 2017

The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function of the Modify Password componen…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-13129

Published Sep 26, 2017

Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrators for requests that…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14680

Published Sep 21, 2017

ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1