PT-2025-43906 · Axosoft · Axosoft Scrum/Bug Tracking

Sn4Ku1

·

Published

2025-10-27

·

Updated

2025-10-27

·

CVE-2025-12249

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Axosoft Scrum and Bug Tracking version 22.1.1.11545
Description A flaw exists in Axosoft Scrum and Bug Tracking that allows for CSV injection. The issue is located in the Edit Ticket Page component, specifically through manipulation of the Title argument. This can be exploited remotely. The exploit is publicly available. The vendor was notified but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2025-12249

Affected Products

Axosoft Scrum/Bug Tracking