PT-2022-16817 · Unknown · Anuko Time Tracker

Indevi0Us

·

Published

2022-02-23

·

Updated

2022-03-04

·

CVE-2022-24708

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Anuko Time Tracker versions prior to 1.20.0.5646
Description Anuko Time Tracker is an open source, web-based time tracking application written in PHP. The issue arises from the ttUser.class.php file not escaping the primary group name for display, allowing a logged-in user to modify it with JavaScript elements. This could lead to the execution of scripts in a user's browser on subsequent requests to pages where the primary group name is displayed.
Recommendations For versions prior to 1.20.0.5646, upgrade to version 1.20.0.5646 to resolve the issue. As a temporary workaround for users unable to upgrade, modify ttUser.class.php to use an additional call to htmlspecialchars when printing the group name.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24708
GHSA-RGCM-XGVJ-5MQH

Affected Products

Anuko Time Tracker