PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabilities that allow unauthenticated attackers to inject arbitrary JavaScript by manipulating URL paths and POST parameters. Attackers can append malicious payloads to login.php, timeclock.php, audit.php, and timerpt.php endpoints, or inject code through from_date and to_date parameters in report requests to execute scripts in user browsers.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-15 19:16
Updated : 2026-06-17 04:18
NVD link : CVE-2021-47967
Mitre link : CVE-2021-47967
CVE.ORG link : CVE-2021-47967
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
