Skip to content
Noroxi

kronos records

7 published records for vendor kronos.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

7 records
  • An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.

    CriticalCVSS 9.8No exploitEPSS 2%

    kronos · web time and attendanceDec 21, 2020

  • CVE-2020-8494
    35Monitor

    In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H402editUser servlet allows an atta

    HighCVSS 8.8No exploitEPSS 1%

    kronos · web time and attendanceJan 30, 2020

  • CVE-2020-8495
    31Monitor

    In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an atta

    HighCVSS 7.5Proof of conceptEPSS 3%

    kronos · web time and attendanceJan 30, 2020

  • A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352premPayRequest servlet's

    MediumCVSS 6.5No exploitEPSS 1%

    kronos · web time and attendanceJul 15, 2020

  • CVE-2020-8493
    19Monitor

    A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fiel

    MediumCVSS 4.8Proof of conceptEPSS 1%

    kronos · web time and attendanceJan 30, 2020

  • CVE-2020-8496
    19Monitor

    In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Applic

    MediumCVSS 4.8No exploitEPSS 1%

    kronos · web time and attendanceJan 30, 2020

  • CVE-2008-6666
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Kronos webTA allow remote attackers to inject arbitrary web script or HTML via the de

    MediumCVSS 4.3No exploitEPSS 1%

    kronos · kronos webtaApr 8, 2009