CVE-2016-20032General

LOWCVSS 5.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads through the 'holiday_name' and 'memo' POST parameters. Attackers can submit crafted requests with script code in these parameters to compromise user browser sessions and steal sensitive information.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-15); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-15: 2Mentions · 2026-03-17: 1Technical Details · 2026-03-15: 203-1503-17
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-152
Disclosure1General1
2026-03-171
General1
Full discourse3 posts
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2016-20032 - ZKTeco Inc. - ZKTeco ZKAccess Security System - https://www.redpacketsecurity.com/cve-alert-cve-2016-20032-zkteco-inc-zkteco-zkaccess-security-system/ #OSINT #ThreatIntel #CyberSecurity #cve-2016-20032 #zkteco-inc #zkteco-zkaccess-security-system

    Post summary

    A concise alert headline linking to an external page, without substantive technical details or actionable information.

    0000073
    3.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2016-20032 - ZKTeco ZKAccess Security System 5.3.1 Stored XSS Intel Report: https://ift.tt/yOcMNUH

    Post summary

    A brief alert announces CVE‑2016‑20032, a stored XSS flaw in ZKTeco ZKAccess Security System 5.3.1, with a link to an Intel report for more details.

    0000036
    336 followersView on X
  • CVE@CVEnew
    General

    CVE-2016-20032 ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injectin… https://www.cve.org/CVERecord?id=CVE-2016-20032

    Post summary

    The post gives a concise disclosure of a stored XSS flaw in ZKTeco ZKAccess Security System 5.3.1 without mentioning PoC, exploit, remediation, or active exploitation.

    0000070
    56.7K followersView on X

Explore more