CVE-2023-51157
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2023-51157 is a Cross-Site Scripting (XSS) vulnerability affecting ZKTeco WDMS version 5.1.3 Pro. An attacker can exploit this flaw by injecting a malicious script into the Emp Name parameter, allowing them to execute arbitrary code and potentially obtain sensitive information from affected users. This vulnerability poses a significant risk, particularly in enterprise environments where the software is used to manage employee information. It is recommended that users upgrade to the latest version of the software or implement mitigations to prevent XSS attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.