Executive brief
ZKTeco ZKBioSecurity, a web-based security platform used for access control and visitor management, contains multiple security flaws. These vulnerabilities allow an attacker to trick a user into clicking a malicious link, which then executes unauthorized scripts in the user's web browser. This could lead to the theft of login sessions, unauthorized access to security management features, or the defacement of the web interface.
Technical details
Multiple reflected cross-site scripting (XSS) vulnerabilities exist in ZKTeco ZKBioSecurity 3.0 (specifically tested on version 3.0.1.0_R_230). The root cause is the improper sanitization of input parameters in several scripts, including 'authRoleAction!getAll.action' and 'authUserAction!getAll.action'. Specifically, parameters such as 'filter:authGroupSet.id' are vulnerable to payload injection. An unauthenticated remote attacker can exploit these by crafting a malicious URL and enticing a logged-in user to click it. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions within the application.
Affected products
- ZKTeco ZKBioSecurity 3.0.1.0_R_230 and earlier
Timeline
- 2016-07-18: disclosed: Vulnerability discovered by Zero Science Lab
- 2016-08-31: advisory: Public advisory released by CXSecurity/Zero Science Lab
- 2026-03-16: advisory: CVE-2016-20027 published/updated in NVD
References
- https://cxsecurity.com/issue/WLB-2016080267
- https://exchange.xforce.ibmcloud.com/vulnerabilities/116476
- https://packetstormsecurity.com/files/138568
- https://www.vulncheck.com/advisories/zkteco-zkbiosecurity-multiple-reflected-xss-vulnerabilities
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5363.php