Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52p7-j296-qwmp

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login Message, Banner Message, and Password Instructions) of the com.threeis.webta.H261configMenu servlet via an authenticated administrator.

A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login Message, Banner Message, and Password Instructions) of the com.threeis.webta.H261configMenu servlet via an authenticated administrator.

EPSS

Процентиль: 79%
0.01249
Низкий

Связанные уязвимости

CVSS3: 4.8
nvd
около 6 лет назад

A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login Message, Banner Message, and Password Instructions) of the com.threeis.webta.H261configMenu servlet via an authenticated administrator.

EPSS

Процентиль: 79%
0.01249
Низкий