CVE-2020-8496
EUVD-2020-2936230.01.2020, 22:15
In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Application Banner input field of the /ApplicationBanner page as an authenticated administrator.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| kronos | web_time_and_attendance | 4.1.26 ≤ 𝑥 < 5.0 |
| kronos | web_time_and_attendance | 4.1.17:r1 |
𝑥
= Vulnerable software versions