PT-2023-23717 · Unknown · Anuko Time Tracker
Indevi0Us
·
Publicado
2023-05-15
·
Atualizado
2023-05-25
·
CVE-2023-32308
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
anuko timetracker versions prior to 1.22.11.5781
Description
The issue is related to a Boolean-based blind SQL injection vulnerability in the invoices.php file of anuko timetracker, an open source time tracking system. This vulnerability existed due to a coding error after validating parameters in POST requests, where there was no check for errors before adjusting the invoice sorting order. As a result, it was possible to craft a POST request with malicious SQL for the Time Tracker database.
Recommendations
For versions prior to 1.22.11.5781, upgrade to version 1.22.11.5781 or later to resolve the issue.
As a temporary workaround for users unable to upgrade, consider inserting an additional check for errors in a condition before calling
ttGroupHelper::getActiveInvoices() in invoices.php.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Anuko Time Tracker