CVE-2023-51157: XSS
Published Sep 25, 2024
·Updated
Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the Emp Name parameter.
Affected Software
1 affected component
ZKTeco WDMS=5.1.3
Event History
Sep 25, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-51157?
CVE-2023-51157 has a high severity rating due to its ability to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2023-51157?
To fix CVE-2023-51157, upgrade ZKTeco WDMS to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2023-51157?
CVE-2023-51157 affects ZKTeco WDMS version 5.1.3, which is part of the ZKTeco ZKBio WDMS software.
4
What types of attacks can exploit CVE-2023-51157?
CVE-2023-51157 can be exploited through cross-site scripting (XSS) attacks targeting the Emp Name parameter.
5
What kind of information can be compromised by CVE-2023-51157?
CVE-2023-51157 can lead to the exposure of sensitive information as a result of arbitrary code execution.