ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-37005”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37005
Published
2026-01-29
CVSS:
7.1
ShadowTrackr CVSS:
5.0
Summary:
TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumerate valid usernames by manipulating the 'notes' parameter. Attackers can inject conditional time delays in the add_entry.php endpoint to determine user existence by measuring response time differences.