CVE-2016-20032 PUBLISHED

ZKTeco ZKAccess Security System 5.3.1 Stored XSS

Assigner: VulnCheck
Reserved: 15.03.2026 Published: 15.03.2026 Updated: 15.03.2026

ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads through the 'holiday_name' and 'memo' POST parameters. Attackers can submit crafted requests with script code in these parameters to compromise user browser sessions and steal sensitive information.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor ZKTeco Inc.
Product ZKTeco ZKAccess Security System
Versions
  • Version 5.3.12252 is affected

Credits

  • LiquidWorm as Gjoko Krstic of Zero Science Lab finder

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE