CVE-2022-38801: ZKTeco BioTime
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cross-site scripting.
Affected products
- ZKTeco BioTime: before 8.5.4 (fixed in 8.5.4)
Published 2022-11-30. Last modified 2026-06-17.