ZKBio Time - CSV Injection (CVE-2022-40472)
Hi all,
I am here with new post. Recently I have identified a csv injection vulnerability in one of the web-based time and attendance management software. Below are the details:
Software Description:
ZKBio Time is a powerful web-based time and attendance management software. With a powerful data handling capacity, the system can manage the attendance data of 10,000 employees. It can easily handle hundreds of devices and thousands of employees and their transactions. ZKBio Time comes with an intuitive user interface is able to manage timetable, shift and schedule and can easily generate attendance reports.
Impacted Version: 8.0.7 (Build: 20220721.14829) and before.
CVE ID: CVE-2022-40472
Vulnerability details:
- Login to ZKBio Time Application
- In the left Menu click on Messages -> Public
- Click on ADD new message button
- Write your Device Serial Number
- Mention any date/time and duration
- In Content Field Add your CSV injection payload.
- As shown below
- Any user who extract the report in CSV format and opens it
- The embedded payload will be executed
Comments
Post a Comment