Cross Site Scripting Vulnerability in Timesheet Next Gen by Timesheet
CVE-2019-1010287
6.1MEDIUM
What is CVE-2019-1010287?
The Timesheet Next Gen application version 1.5.3 and earlier is susceptible to a Cross Site Scripting (XSS) vulnerability. This flaw allows an attacker to execute arbitrary HTML and JavaScript code through a maliciously crafted 'redirect' parameter in the web login form (login.php). When a victim unknowingly clicks on a harmful URL, it can lead to exposure of sensitive information or unauthorized actions within their session.
Affected Version(s)
Timesheet Next Gen 1.5.3 and earlier
