Описание
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with Timekeeper or Supervisor privileges to gain unauthorized administrative privileges within the application via the delegate, delegateRole, and delegatorUserId parameters.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ProductVendor Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ProductVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 3.8 (включая) до 4.0 (исключая)
cpe:2.3:a:kronos:web_time_and_attendance:*:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04966
Низкий
7.5 High
CVSS3
7.5 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-862
Связанные уязвимости
github
больше 3 лет назад
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with Timekeeper or Supervisor privileges to gain unauthorized administrative privileges within the application via the delegate, delegateRole, and delegatorUserId parameters.
EPSS
Процентиль: 89%
0.04966
Низкий
7.5 High
CVSS3
7.5 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-862