CVE Database
/

CVE-2019-1010287

Back to search

CVE-2019-1010287

Published: Jul 17, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

Timesheet Next Gen 1.5.3 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via a "redirect" parameter. The component is: Web login form: login.php, lines 40 and 54. The attack vector is: reflected XSS, victim may click the malicious url.

VendorProductVersions

Timesheet Next Gen

Timesheet Next Gen

affected
1.5.3 and earlier

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now