PT-2022-2499 · Anuko · Anuko Time Tracker
Indevi0Us
·
Published
2022-02-23
·
Updated
2022-05-12
·
CVE-2022-24707
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Anuko Time Tracker versions prior to 1.20.0.5642
Description
The issue is related to the Time Tracker Puncher plugin, which reused code from other places and relied on an unsanitized
date parameter in POST requests. This allowed for the crafting of malicious SQL requests for the Time Tracker database. The vulnerability can be exploited remotely, enabling an attacker to execute arbitrary SQL queries in the Time Tracker database.Recommendations
For versions prior to 1.20.0.5642, upgrade to version 1.20.0.5642 to resolve the issue.
For users unable to upgrade, add their own checks to input to mitigate the risk. As a temporary workaround, consider adding validation to the
date parameter in POST requests to prevent malicious SQL injection.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anuko Time Tracker