kronos records
7 published records for vendor kronos.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-862 Missing Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-35604No exploit | An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.kronos · web time and attendance · CWE-611 | Critical9.8 | — | 1.7% | Dec 21, 2020 |
35Monitor | CVE-2020-8494No exploit | In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H402editUser servlet allows an attakronos · web time and attendance | High8.8 | — | 1.1% | Jan 30, 2020 |
31Monitor | CVE-2020-8495Proof of concept | In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attakronos · web time and attendance · CWE-862 | High7.5 | — | 3.1% | Jan 30, 2020 |
26Monitor | CVE-2020-14982No exploit | A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352premPayRequest servlet'skronos · web time and attendance · CWE-89 | Medium6.5 | — | 1.3% | Jul 15, 2020 |
19Monitor | CVE-2020-8493Proof of concept | A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fielkronos · web time and attendance · CWE-79 | Medium4.8 | — | 1.5% | Jan 30, 2020 |
19Monitor | CVE-2020-8496No exploit | In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Applickronos · web time and attendance · CWE-79 | Medium4.8 | — | 0.5% | Jan 30, 2020 |
17Monitor | CVE-2008-6666No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Kronos webTA allow remote attackers to inject arbitrary web script or HTML via the dekronos · kronos webta · CWE-79 | Medium4.3 | — | 1.2% | Apr 8, 2009 |
- CVE-2020-3560439Monitor
An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.
CriticalCVSS 9.8No exploitEPSS 2%kronos · web time and attendanceDec 21, 2020
- CVE-2020-849435Monitor
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H402editUser servlet allows an atta
HighCVSS 8.8No exploitEPSS 1%kronos · web time and attendanceJan 30, 2020
- CVE-2020-849531Monitor
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an atta
HighCVSS 7.5Proof of conceptEPSS 3%kronos · web time and attendanceJan 30, 2020
- CVE-2020-1498226Monitor
A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352premPayRequest servlet's
MediumCVSS 6.5No exploitEPSS 1%kronos · web time and attendanceJul 15, 2020
- CVE-2020-849319Monitor
A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fiel
MediumCVSS 4.8Proof of conceptEPSS 1%kronos · web time and attendanceJan 30, 2020
- CVE-2020-849619Monitor
In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Applic
MediumCVSS 4.8No exploitEPSS 1%kronos · web time and attendanceJan 30, 2020
- CVE-2008-666617Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Kronos webTA allow remote attackers to inject arbitrary web script or HTML via the de
MediumCVSS 4.3No exploitEPSS 1%kronos · kronos webtaApr 8, 2009