CVE-2022-38801: XSS
Published Nov 30, 2022
·Updated
In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cross-site scripting.
Affected Software
1 affected component
Zkteco BioTime<8.5.4
Event History
Nov 30, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-38801.
2
What is the severity of CVE-2022-38801?
The severity of CVE-2022-38801 is medium with a CVSS score of 5.4.
3
What is the affected software for CVE-2022-38801?
The affected software for CVE-2022-38801 is ZKTeco BioTime versions up to 8.5.4.
4
What is the description of CVE-2022-38801?
CVE-2022-38801 is a vulnerability in ZKTeco BioTime < 8.5.3 Build:20200816.447 that allows an employee to hijack an administrator session and cookies using blind cross-site scripting.
5
How can I fix CVE-2022-38801 to protect my system?
To fix CVE-2022-38801, you should update ZKTeco BioTime to version 8.5.4 or later.