CVE-2022-38802: XSS
Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual log, time interval, attshift, and holiday. An authenticated administrator can read local files by exploiting XSS into a pdf generator when exporting data as a PDF
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38802?
CVE-2022-38802 is a vulnerability in Zkteco BioTime < 8.5.3 Build:20200816.447 that allows an authenticated administrator to read local files by exploiting XSS into a PDF generator when exporting data as a PDF.
How severe is CVE-2022-38802?
CVE-2022-38802 has a severity rating of 6.2, which is considered medium.
How can an attacker exploit CVE-2022-38802?
An attacker can exploit CVE-2022-38802 by using various methods such as resign, private message, manual log, time interval, attshift, and holiday to gain incorrect access control and exploit XSS into a PDF generator.
Which versions of Zkteco BioTime are affected by CVE-2022-38802?
Zkteco BioTime versions before 8.5.4 are affected by CVE-2022-38802.
Are there any fixes available for CVE-2022-38802?
It is recommended to update Zkteco BioTime to version 8.5.4 or later to fix the vulnerability CVE-2022-38802.