ZKTeco ZKBioSecurity 3.0 Multiple...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Summary ZKBioSecurity3.0 is the ultimate "All in One" web based security platform developed by ZKTeco. It contains four integrated modules: access control, video linkage, elevator control and visitor management. With an optimized system architecture designed for high level biometric identification and a modern-user friendly UI, ZKBioSecurity 3.0 provides the most advanced solution for a whole new user experience. ### Description ZKBioSecurity suffers from multiple reflected XSS vulnerabilities when input passed via several parameters to several scripts is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. ### Vendor ZKTeco Inc. - http://www.zkteco.com ### Affected Version * 3.0.1.0_R_230 * Platform: 3.0.1.0_R_230 * Personnel: 1.0.1.0_R_1916 * Access: 6.0.1.0_R_1757 * Elevator: 2.0.1.0_R_777 * Visitor: 2.0.1.0_R_877 * Video:2.0.1.0_R_489 * Adms:...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息