Security Advisory

CVE-2022-40472

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-09-29 19:02:07
Last updated 2025-05-20 20:05:27
Assigner mitre
State PUBLISHED

Description

ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the Content text field of the Add New Message module.