PT-2017-15149 · Biometric Shift · Biometric Shift Employee Management System

52Pojie

·

Published

2017-12-30

·

Updated

2018-01-09

·

CVE-2017-17993

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Biometric Shift Employee Management System (affected versions not specified)
Description The issue concerns a problem where an attacker can execute malicious scripts. This is possible due to the lack of proper validation of user input in the amount parameter of a specific request to 'index.php?user=addition deduction'.
Recommendations As a temporary workaround, consider restricting access to the 'index.php?user=addition deduction' endpoint until a patch is available. Avoid using the amount parameter in this endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17993

Affected Products

Biometric Shift Employee Management System