Loading
There is a reflected XSS vulnerability in ZKTime Web 2.0.1.12280. The vulnerability exists due to insufficient filtration of user-supplied data in the 'Range' field of the 'Department' module in a Personnel Advanced Query. A remote attacker can execute arbitrary HTML and script code in the browser in the context of the vulnerable application.
Use CWE-79, Zkteco vendor hub and Zktime Web product page to widen CVE-2017-17057 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-17056, CVE-2017-13129 and CVE-2017-14680 for nearby disclosures in the same product family.