5.4
CVSSv3

CVE-2017-16819

Published: 17/11/2017 Updated: 04/12/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A stored cross-site scripting vulnerability in the Icon Time Systems RTC-1000 v2.5.7458 and previous versions time clock allows remote malicious users to inject arbitrary JavaScript in the nameFirst (aka First Name) field for the employee details page (/employee.html) that is then reflected in multiple pages where that field data is utilized, resulting in session hijacking and possible elevation of privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

icontime rtc-1000_firmware

Exploits

# Exploit Title: Icon Time Systems RTC-1000 (<= v257458) Universal Time Clocks Stored XSS Vulnerability # Date: 17-11-2017 # Vendor: wwwicontimecom/ # Version: <= v257458 # Exploit Author: Keith Thome # Contact: twittercom/keiththome # Website: wwwkeiththomecom/rtc-1000-vuln # CVE: CVE-2017-16819 # Type: Remote ...