Timesheet · Timesheet Next Gen · CVE-2019-1010287
Name of the Vulnerable Software and Affected Versions:
Timesheet Next Gen versions 1.5.3 and earlier
Description:
The issue allows an attacker to execute arbitrary HTML and JavaScript code via a `redirect` parameter. This is a reflected Cross Site Scripting (XSS) attack, where the victim may click on a malicious URL. The vulnerable component is the Web login form, specifically the `login.php` file at lines 40 and 54.
Recommendations:
For Timesheet Next Gen versions 1.5.3 and earlier, as a temporary workaround, consider restricting access to the `login.php` file until a patch is available. Avoid using the `redirect` parameter in the Web login form to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.