TimeClock Software Vulnerabilities and Affected Products
Vulnerabilities associated with TimeClock Software.
Products
Clear product- TimeClock Software1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-37005HIGH | TimeClock Software 1.01 Authenticated Time-Based SQL InjectionTimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumerate valid usernames by manipulating the 'notes' parameter. Attackers can inject conditional time delays in the add_entry.php endpoint to determine user existence by measuring response time differences. CWE-89Jan 29, 2026 | CVSS7.1v4.0 | EPSS0.264% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |