3.5
CVSSv2

CVE-2020-8496

Published: 30/01/2020 Updated: 05/02/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions prior to 5.0, there is a Stored XSS vulnerability by setting the Application Banner input field of the /ApplicationBanner page as an authenticated administrator.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kronos web time and attendance 4.1.17

kronos web time and attendance