PoC Index

CVE-2020-8493

MEDIUM 6.9EPSS 1.5%

A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login Message, Banner Message, and Password Instructions) of the com.threeis.webta.H261configMenu servlet via an authenticated administrator.

CVSS v3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS v3.0
6.9 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
1.49% chance of exploitation in the next 30 days, 72th percentile
Published
2020-01-30
Updated
2024-08-04

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related