PT-2026-41346 · Timeclock · Php Timeclock

Tyler Butler

·

Published

2026-05-15

·

Updated

2026-05-15

·

CVE-2021-47967

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabilities that allow unauthenticated attackers to inject arbitrary JavaScript by manipulating URL paths and POST parameters. Attackers can append malicious payloads to login.php, timeclock.php, audit.php, and timerpt.php endpoints, or inject code through from date and to date parameters in report requests to execute scripts in user browsers.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-47967

Affected Products

Php Timeclock