Back to search
CVE-2019-1010287
Published: Jul 17, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
Timesheet Next Gen 1.5.3 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via a "redirect" parameter. The component is: Web login form: login.php, lines 40 and 54. The attack vector is: reflected XSS, victim may click the malicious url.
| Vendor | Product | Versions |
|---|---|---|
Timesheet Next Gen | Timesheet Next Gen | affected 1.5.3 and earlier |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now