CVE-2017-17989: Iwcnetwork Biometric Shift Employee Management System

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Biometric Shift Employee Management System has XSS via the index.php holiday_name parameter in an edit_holiday action.

Affected products

  • Iwcnetwork Biometric Shift Employee Management System: version 4.0 only

Published 2017-12-30. Last modified 2026-06-17.