A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352premPayRequest servlet's SortBy parameter) allows an attacker with the Employee, Supervisor, or Timekeeper role to read sensitive data from the database.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-07-15T20:09:33

Updated: 2024-08-04T13:00:52.138Z

Reserved: 2020-06-22T00:00:00

Link: CVE-2020-14982

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-07-15T21:15:12.380

Modified: 2020-07-22T17:26:41.003

Link: CVE-2020-14982

cve-icon Redhat

No data.