In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Application Banner input field of the /ApplicationBanner page as an authenticated administrator.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-01-30T21:17:59
Updated: 2024-08-04T10:03:44.861Z
Reserved: 2020-01-30T00:00:00
Link: CVE-2020-8496
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2020-01-30T22:15:10.640
Modified: 2020-02-05T21:28:43.177
Link: CVE-2020-8496
Redhat
No data.