PT-2017-15149 · Biometric Shift · Biometric Shift Employee Management System
52Pojie
·
Published
2017-12-30
·
Updated
2018-01-09
·
CVE-2017-17993
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Biometric Shift Employee Management System (affected versions not specified)
Description
The issue concerns a problem where an attacker can execute malicious scripts. This is possible due to the lack of proper validation of user input in the
amount parameter of a specific request to 'index.php?user=addition deduction'.Recommendations
As a temporary workaround, consider restricting access to the 'index.php?user=addition deduction' endpoint until a patch is available. Avoid using the
amount parameter in this endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Biometric Shift Employee Management System