VulnerabilityModified
CVE-2020-14982
A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352premPayRequest servlet's SortBy parameter) allows an attacker with the Employee, Supervisor, or Timekeeper role to read sensitive data…
MEDIUM 6.5EPSS 1.28%
Does this matter?
Lower severity and a low EPSS score (1.28%). Track it; it rarely justifies an emergency change on its own.
Description
A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352premPayRequest servlet's SortBy parameter) allows an attacker with the Employee, Supervisor, or Timekeeper role to read sensitive data from the database.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.28% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- kronos/web time and attendance
- Source
- cve@mitre.org
References
- https://www.mindpointgroup.com/articles/Third Party Advisory
- https://www.mindpointgroup.com/blog/webta-sqli-vulnerability/Exploit, Third Party Advisory
- https://www.mindpointgroup.com/articles/Third Party Advisory
- https://www.mindpointgroup.com/blog/webta-sqli-vulnerability/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.