Descripción
ZKTeco ZKBioSecurity 3.0 contains multiple reflected cross-site scripting vulnerabilities that allow attackers to execute arbitrary HTML and script code by injecting malicious payloads through unsanitized parameters in scripts. Attackers can craft URLs with XSS vulnerable scripts a user's browser session within the context of affected application.
https://cxsecurity.com/issue/WLB-2016080267
https://exchange.xforce.ibmcloud.com/vulnerabilities/116476
https://packetstormsecurity.com/files/138568
https://www.vulncheck.com/advisories/zkteco-zkbiosecurity-multiple-reflected-xss-vulnerabilities
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5363.php