Skip to main content

Vendor/product archive

anuko / time_tracker CVEs

Beta · best-effort

12 CVEs tagged to anuko / time_tracker1 Critical, 7 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2023-32308

Published May 15, 2023

anuko timetracker is an open source time tracking system. Boolean-based blind SQL injection vulnerability existed in Time Tracker invoices.php in versions prior to 1.22.11.5781. T…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32306

Published May 12, 2023

Time Tracker is an open source time tracking system. A time-based blind injection vulnerability existed in Time Tracker reports in versions prior to 1.22.13.5792. This was happeni…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32066

Published May 9, 2023

Time Tracker is an open source time tracking system. The week view plugin in Time Tracker versions 1.22.11.5782 and prior was not escaping titles for notes in week view table. Bec…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24708

Published Feb 24, 2022

Anuko Time Tracker is an open source, web-based time tracking application written in PHP. ttUser.class.php in Time Tracker versions prior to 1.20.0.5646 was not escaping primary g…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24707

Published Feb 24, 2022

Anuko Time Tracker is an open source, web-based time tracking application written in PHP. UNION SQL injection and time-based blind injection vulnerabilities existed in Time Tracke…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43851

Published Dec 22, 2021

Anuko Time Tracker is an open source, web-based time tracking application written in PHP. SQL injection vulnerability exist in multiple files in Time Tracker version 1.19.33.5606…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41139

Published Oct 13, 2021

Anuko Time Tracker is an open source, web-based time tracking application written in PHP. When a logged on user selects a date in Time Tracker, it is being passed on via the date…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29436

Published Apr 13, 2021

Anuko Time Tracker is an open source, web-based time tracking application written in PHP. In Time Tracker before version 1.19.27.5431 a Cross site request forgery (CSRF) vulnerabi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21352

Published Mar 3, 2021

Anuko Time Tracker is an open source, web-based time tracking application written in PHP. In TimeTracker before version 1.19.24.5415 tokens used in password reset feature in Time…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27423

Published Nov 16, 2020

Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27422

Published Nov 16, 2020

In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15255

Published Oct 16, 2020

In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1