PT-2025-43906 · Axosoft · Axosoft Scrum/Bug Tracking

Sn4Ku1

·

Publicado

2025-10-27

·

Atualizado

2025-10-27

·

CVE-2025-12249

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Axosoft Scrum and Bug Tracking version 22.1.1.11545
Description A flaw exists in Axosoft Scrum and Bug Tracking that allows for CSV injection. The issue is located in the Edit Ticket Page component, specifically through manipulation of the Title argument. This can be exploited remotely. The exploit is publicly available. The vendor was notified but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-12249

Produtos afetados

Axosoft Scrum/Bug Tracking