CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. It involves a SQL injection risk.
CVE
CVE-2020-14982
Severity
MEDIUM
CVSS
6.5
EPSS
1.28%
Original NVD Description
A Blind SQL Injection vulnerability in Kronos WebTA 3.8.x and later before 4.0 (affecting the com.threeis.webta.H352premPayRequest servlet's SortBy parameter) allows an attacker with the Employee, Supervisor, or Timekeeper role to read sensitive data from the database.
Related CVEs
Other vulnerabilities affecting the same vendor(s)