CVE-2016-20027 PUBLISHED

ZKTeco ZKBioSecurity 3.0 Multiple Reflected XSS Vulnerabilities

Assigner: VulnCheck
Reserved: 15.03.2026 Published: 15.03.2026 Updated: 15.03.2026

ZKTeco ZKBioSecurity 3.0 contains multiple reflected cross-site scripting vulnerabilities that allow attackers to execute arbitrary HTML and script code by injecting malicious payloads through unsanitized parameters in multiple scripts. Attackers can craft malicious URLs with XSS payloads in vulnerable parameters to execute scripts in a user's browser session within the context of the affected application.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor ZKTeco Inc.
Product ZKTeco ZKBioSecurity
Versions
  • Version 3.0.1.0_R_230 is affected

Credits

  • LiquidWorm as Gjoko Krstic of Zero Science Lab finder

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE