PT-2022-2499 · Anuko · Anuko Time Tracker

Indevi0Us

·

Published

2022-02-23

·

Updated

2022-05-12

·

CVE-2022-24707

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Anuko Time Tracker versions prior to 1.20.0.5642
Description The issue is related to the Time Tracker Puncher plugin, which reused code from other places and relied on an unsanitized date parameter in POST requests. This allowed for the crafting of malicious SQL requests for the Time Tracker database. The vulnerability can be exploited remotely, enabling an attacker to execute arbitrary SQL queries in the Time Tracker database.
Recommendations For versions prior to 1.20.0.5642, upgrade to version 1.20.0.5642 to resolve the issue. For users unable to upgrade, add their own checks to input to mitigate the risk. As a temporary workaround, consider adding validation to the date parameter in POST requests to prevent malicious SQL injection.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02909
CVE-2022-24707
GHSA-WQX7-95FX-WJXJ

Affected Products

Anuko Time Tracker