CVE-2022-40472
EUVD-2022-4375029.09.2022, 20:15
ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the Content text field of the Add New Message module.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| zktec | zkbio_time | 8.0.7 |
𝑥
= Vulnerable software versions