CVE-2020-8493 describes a stored Cross-Site Scripting (XSS) vulnerability in Kronos Web Time and Attendance (webTA) versions 3.8.x and later 3.x before 4.0. An authenticated administrator can inject malicious scripts into the Login Message, Banner Message, or Password Instructions fields via the com.threeis.webta.H261configMenu servlet. This vulnerability has a CVSS score of 4.8 (Medium), indicating a low-complexity attack requiring high privileges and user interaction, potentially leading to limited impact on confidentiality and integrity. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry exists for "Authenticated Remote Privilege Escalation," and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.8, < 4.0CPE matchmatch criteria | cpe:2.3:a:kronos:web_time_and_attendance:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.