CVE-2024-35432: XSS
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Cross Site Scripting (XSS) via an Audio File. An authenticated user can injection malicious JavaScript code to trigger a Cross Site Scripting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35432?
CVE-2024-35432 is considered a significant vulnerability due to its potential for Cross Site Scripting (XSS) attacks.
How do I fix CVE-2024-35432?
To fix CVE-2024-35432, update ZKTeco ZKBio CVSecurity to the latest version provided by the vendor that addresses this vulnerability.
What type of attack can be executed using CVE-2024-35432?
CVE-2024-35432 can be exploited by an attacker to execute Cross Site Scripting (XSS) attacks through an audio file.
Who is affected by CVE-2024-35432?
Users of ZKTeco ZKBio CVSecurity version 6.1.1 are affected by CVE-2024-35432.
Can CVE-2024-35432 affect client-side applications?
Yes, CVE-2024-35432 can affect client-side applications by enabling the injection of malicious JavaScript into the web environment.