S4E just found a low-severity finding from missing http security headers implementation scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2019-1010287

6.1
CVSS
Description

Timesheet Next Gen 1.5.3 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via a "redirect" parameter. The component is: Web login form: login.php, lines 40 and 54. The attack vector is: reflected XSS, victim may click the malicious url.

Attack Vector
-
Privileges Req.
-
User Interaction
-
timesheet next gen
Updated Sep 28, 2026View on NVD →
S4E scanner

CVE history: timesheet next gen

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →