In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Application Banner input field of the /ApplicationBanner page as an authenticated administrator.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.kronos.com/products/kronos-webta | product vendor advisory |
http://www.nolanbkennedy.com/post/stored-xss-2-in-kronos-web-time-and-attendance-webta | third party advisory exploit |