header-logo
Suggest Exploit
vendor:
Kronos WebTA
by:
Nolan B. Kennedy (nxkennedy)
4.8
CVSS
MEDIUM
Authenticated Remote Privilege Escalation
264
CWE
Product Name: Kronos WebTA
Affected Version From: 3.8.x
Affected Version To: 4.0
Patch Exists: YES
Related CWE: CVE-2020-8495, CVE-2020-8493
CPE: a:kronos:webta
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: Linux
2019

Kronos WebTA 4.0 – Authenticated Remote Privilege Escalation

Exploit abuses delegation privs present in the WebTA "/servlet/com.threeis.webta.H491delegate" servlet. By specifying the "delegate" and "delegatorUserId" parameter an attacker can use an admin user id to delegate role 5 (aka admin privs) to any other known user id, including oneself. With the new admin account, an attacker can abuse a stored XSS vulnerability present in the login page, banner (displayed on every page) & password reset page. An attacker can also pull system information and download a file containing the FULL NAME AND SSN OF EVERY USER in the database (typically thousands).

Mitigation:

Ensure that the WebTA application is up to date and that all users have strong passwords.
Source

Exploit-DB raw data: