CVE-2023-51157: ZKTeco Wdms

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the Emp Name parameter.

Affected products

  • ZKTeco Wdms: version 5.1.3 only

Published 2024-09-25. Last modified 2026-06-17.