CVE-2020-8496
30.01.2020, 22:15
In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Application Banner input field of the /ApplicationBanner page as an authenticated administrator.
Vendor | Product | Version |
---|---|---|
kronos | web_time_and_attendance | 4.1.26 ≤ 𝑥 < 5.0 |
kronos | web_time_and_attendance | 4.1.17:r1 |
𝑥
= Vulnerable software versions