Vulnerability Description
TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumerate valid usernames by manipulating the 'notes' parameter. Attackers can inject conditional time delays in the add_entry.php endpoint to determine user existence by measuring response time differences.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://web.archive.org/web/20190104104315/http://timeclock-software.net/
- https://www.exploit-db.com/exploits/48874
- https://www.vulncheck.com/advisories/timeclock-software-authenticated-time-based
FAQ
What is CVE-2020-37005?
CVE-2020-37005 is a vulnerability with a CVSS score of 7.1 (HIGH). TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumerate valid usernames by manipulating the 'notes' parameter. Attackers can inject ...
How severe is CVE-2020-37005?
CVE-2020-37005 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-37005?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.