CVE-2022-38803: XSS
Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authenticated employee can read local files by exploiting XSS into a pdf generator when exporting data as a PDF
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Zkteco BioTime?
The vulnerability ID for Zkteco BioTime is CVE-2022-38803.
What is the severity of CVE-2022-38803?
The severity of CVE-2022-38803 is medium with a CVSS score of 6.8.
What is the affected software version for CVE-2022-38803?
The affected software version for CVE-2022-38803 is Zkteco BioTime up to exclusive version 8.5.4.
How can an authenticated employee exploit CVE-2022-38803?
An authenticated employee can exploit CVE-2022-38803 by using XSS to exploit the PDF generator when exporting data as a PDF.
Are there any references related to CVE-2022-38803?
Yes, you can find references related to CVE-2022-38803 at the following links: [Link 1](https://gist.github.com/hamoshwani/44653bfe7b8cc461692a2f074b1ef475) and [Link 2](https://www.zkteco.com/).