packetstormsecurity.com
http://packetstormsecurity.com/files/156215/Kronos-WebTA-4.0-Privilege-Escalation-Cross-Site-Scripting.html CVE-2020-8495
HIGH
Kronos WebTA 4.0 - Authenticated Remote Privilege Escalation
Record summary
CVE-2020-8495 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with Timekeeper or Supervisor privileges to gain unauthorized administrative privileges within the application via the delegate, delegateRole, and delegatorUserId parameters.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBKronos WebTA 4.0 - Authenticated Remote Privilege EscalationExploitDB exploitby nxkennedyNot analyzed1 file
References
4nolanbkennedy.com
http://www.nolanbkennedy.com/post/privilege-escalation-in-kronos-web-time-and-attendance-webta nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-8495 kronos.com
https://www.kronos.com/products/kronos-webta