CVE-2017-16819
Current Description
A stored cross-site scripting vulnerability in the Icon Time Systems RTC-1000 v2.5.7458 and earlier time clock allows remote attackers to inject arbitrary JavaScript in the nameFirst (aka First Name) field for the employee details page (/employee.html) that is then reflected in multiple pages where that field data is utilized, resulting in session hijacking and possible elevation of privileges.
Basic Data
Published | November 17, 2017 |
Last Modified | December 04, 2017 |
Assigner | cve@mitre.org |
Data Type | CVE |
Data Format | MITRE |
Data Version | 4.0 |
Problem Type | CWE-79 |
CVE Data Version | 4.0 |
Base Metric V2
CVSS 2 - Version | 2.0 |
CVSS 2 - Vector String | AV:N/AC:M/Au:S/C:N/I:P/A:N |
CVSS 2 - Access Vector | NETWORK |
CVSS 2 - Access Complexity | MEDIUM |
CVSS 2 - Authentication | SINGLE |
CVSS 2 - Confidentiality Impact | NONE |
CVSS 2 - Availability Impact | NONE |
CVSS 2 - Base Score | 3.5 |
Severity | LOW |
Exploitability Score | 6.8 |
Impact Score | 2.9 |
Obtain All Privilege | false |
Obtain User Privilege | false |
Obtain Other Privilege | false |
Base Metric V3
CVSS 3 - Version | 3.0 |
CVSS 3 - Vector String | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
CVSS 3 - Attack Vector | NETWORK |
CVSS 3 - Attack Complexity | LOW |
CVSS 3 - Privileges Required | LOW |
CVSS 3 - User Interaction | REQUIRED |
CVSS 3 - Scope | CHANGED |
CVSS 3 - Confidentiality Impact | LOW |
CVSS 3 - Integrity Impact | LOW |
CVSS 3 - Availability Impact | NONE |
CVSS 3 - Base Score | 5.4 |
CVSS 3 - Base Severity | MEDIUM |
Exploitability Score | 2.3 |
Base Severity | MEDIUM |
Configurations
-
AND
-
OR - Configuration 1
Cpe Version | Part | Vendor | Product | Version | Update | Edition | Language | SW Edition | Target SW | Target HW | Other | Version Start Including | Version End Including | Version Start Excluding | Version End Excluding |
2.3 | OS | Icontime | Rtc-1000 Firmware | * | * | * | * | * | * | * | * | |