CVE-2020-8493
A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login Message, Banner Message, and Password Instructions) of the com.threeis.webta.H261configMenu servlet via…
Does this matter?
Lower severity and a low EPSS score (1.49%). Track it; it rarely justifies an emergency change on its own.
Description
A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login Message, Banner Message, and Password Instructions) of the com.threeis.webta.H261configMenu servlet via an authenticated administrator.
- CVSS 3.1
- 4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.49% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- kronos/web time and attendance
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/156215/Kronos-WebTA-4.0-Privilege-Escalation-Cross-Site-Scripting.htmlExploit, Third Party Advisory
- http://www.nolanbkennedy.com/post/stored-xss-in-kronos-web-time-and-attendance-webtaExploit, Third Party Advisory
- https://www.kronos.com/products/kronos-webtaProduct, Vendor Advisory
- http://packetstormsecurity.com/files/156215/Kronos-WebTA-4.0-Privilege-Escalation-Cross-Site-Scripting.htmlExploit, Third Party Advisory
- http://www.nolanbkennedy.com/post/stored-xss-in-kronos-web-time-and-attendance-webtaExploit, Third Party Advisory
- https://www.kronos.com/products/kronos-webtaProduct, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.