Iwcnetwork develops employee management and biometric shift-scheduling software that serves as a personnel and access-control touchpoint for many organizations. Its vulnerability profile centers on its core shift-management product and recurs through web application weakness classes including cross-site scripting, cross-site request forgery, and path-traversal flaws that reflect input-handling and access-control challenges typical of web-facing administrative platforms. The vendor's disclosures skew toward serious outcomes and frequently acquire public exploit code, making timely patching of exposed instances a priority for defenders. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iwcnetwork over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17876HIGH Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request with a pathname in the path parameter. | Dec 27, 2017 | 7.5 | 36 | NO | YES |
CVE-2017-17992CRITICAL Biometric Shift Employee Management System allows Arbitrary File Download via directory traversal sequences in the index.php form_file_name parameter in a download_form action. | Dec 30, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-17990HIGH Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action. | Dec 30, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-17995MEDIUM Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request. | Dec 30, 2017 | 5.4 | 19 | NO | NO |
CVE-2017-17994MEDIUM Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request. | Dec 30, 2017 | 5.4 | 19 | NO | NO |
CVE-2017-17993MEDIUM Biometric Shift Employee Management System has XSS via the amount parameter in an index.php?user=addition_deduction request. | Dec 30, 2017 | 5.4 | 19 | NO | NO |
CVE-2017-17991MEDIUM Biometric Shift Employee Management System has XSS via the expense_name parameter in an index.php?user=expenses request. | Dec 30, 2017 | 5.4 | 19 | NO | NO |
CVE-2017-17989MEDIUM Biometric Shift Employee Management System has XSS via the index.php holiday_name parameter in an edit_holiday action. | Dec 30, 2017 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iwcnetwork.
Media articles that mention a CVE ID that affects a product developed by Iwcnetwork — matched by CVE ID, not by vendor name.