CVE-2017-17057: XSS
There is a reflected XSS vulnerability in ZKTime Web 2.0.1.12280. The vulnerability exists due to insufficient filtration of user-supplied data in the 'Range' field of the 'Department' module in a Personnel Advanced Query. A remote attacker can execute arbitrary HTML and script code in the browser in the context of the vulnerable application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17057?
The severity of CVE-2017-17057 is medium, with a severity value of 6.1.
What software is affected by CVE-2017-17057?
ZKTime Web version 2.0.1.12280 is affected by CVE-2017-17057.
What is the vulnerability in CVE-2017-17057?
CVE-2017-17057 is a reflected XSS vulnerability in the 'Range' field of the 'Department' module in a Personnel Advanced Query in ZKTime Web 2.0.1.12280.
How does CVE-2017-17057 exploit work?
An attacker can execute arbitrary HTML and script code in the browser by injecting malicious code into the 'Range' field of the 'Department' module in a Personnel Advanced Query in ZKTime Web 2.0.1.12280.
How can I fix CVE-2017-17057?
To fix CVE-2017-17057, it is recommended to update to a patched version of ZKTime Web that includes the necessary filtration of user-supplied data in the 'Range' field.