CVE-2016-20032
Severity CVSS v4.0:
MEDIUM
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
16/03/2026
Last modified:
15/04/2026
Description
ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads through the 'holiday_name' and 'memo' POST parameters. Attackers can submit crafted requests with script code in these parameters to compromise user browser sessions and steal sensitive information.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
7.20
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://cxsecurity.com/issue/WLB-2016090004
- https://exchange.xforce.ibmcloud.com/vulnerabilities/116479
- https://packetstormsecurity.com/files/138572
- https://www.exploit-db.com/exploits/40328/
- https://www.vulncheck.com/advisories/zkteco-zkaccess-security-system-stored-xss
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5368.php



