PT-2021-23136 · Unknown · Anuko Time Tracker

Indevi0Us

·

Published

2021-10-18

·

Updated

2021-10-22

·

CVE-2021-41156

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions anuko/timetracker versions prior to 1.19.30.5601
Description The issue concerns anuko/timetracker, an open-source time tracking system. In affected versions, the system uses a browser today hidden control to collect the current date from user browsers. Due to the lack of sanity checks on this parameter in versions prior to 1.19.30.5601, it is possible to craft an HTML form with malicious JavaScript. An attacker could use social engineering to convince logged-on users to execute a POST request from such a form, resulting in the execution of attacker-supplied JavaScript in the user's browser.
Recommendations For versions prior to 1.19.30.5601, upgrade to version 1.19.30.5601 or later. If an upgrade is not practical, introduce the ttValidDbDateFormatDate function as in the latest version and add a call to it within the access checks block.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41156
GHSA-G9CC-M4P4-6XPC

Affected Products

Anuko Time Tracker