CVE-2020-14982
Summary
| CVE | CVE-2020-14982 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-15 21:15:00 UTC |
| Updated | 2020-07-22 17:26:00 UTC |
| Description | A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352premPayRequest servlet's SortBy parameter) allows an attacker with the Employee, Supervisor, or Timekeeper role to read sensitive data from the database. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kronos | Web Time And Attendance | All | All | All | All |
| Application | Kronos | Web Time And Attendance | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security News and Updates from the Team at MindPoint Group | MISC | www.mindpointgroup.com | Third Party Advisory |
| WebTA SQLi Vulnerability | MISC | www.mindpointgroup.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.