PT-2023-23715 · Unknown · Time Tracker

Indevi0Us

·

Published

2023-05-12

·

Updated

2023-05-24

·

CVE-2023-32306

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Time Tracker versions prior to 1.22.13.5792
Description A time-based blind injection issue existed in Time Tracker reports due to the reports.php page not validating all parameters in POST requests. This allowed malicious SQL to be crafted for the Time Tracker database. The issue is related to the lack of validation of parameters in POST requests, which could be exploited by crafting malicious requests.
Recommendations For versions prior to 1.22.13.5792, update to version 1.22.13.5792 to resolve the issue. As a temporary workaround, consider using the fixed code in ttReportHelper.class.php from version 1.22.13.5792.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-32306
GHSA-758X-VG7G-J9J3

Affected Products

Time Tracker