📦 Time Tracker

by Anuko

🔍 What is Time Tracker?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-27422

CRITICAL CVSS 9.8 Nov 16, 2020

This vulnerability in Anuko Time Tracker allows attackers to reuse password reset links after they've already been used, enabling account takeover. It affects all users of the vulnerable version who r...

CVE-2023-32308

HIGH CVSS 8.2 May 15, 2023

Anuko Time Tracker versions before 1.22.11.5781 contain a blind SQL injection vulnerability in invoices.php that allows attackers to execute arbitrary SQL queries via crafted POST requests. This can l...

CVE-2023-32306

HIGH CVSS 8.8 May 12, 2023

CVE-2023-32306 is a time-based blind SQL injection vulnerability in Time Tracker's reports.php page that allows attackers to execute arbitrary SQL queries against the database. This affects all Time T...

CVE-2022-24707

HIGH CVSS 7.4 Feb 24, 2022

CVE-2022-24707 is a SQL injection vulnerability in Anuko Time Tracker's Puncher plugin that allows attackers to execute arbitrary SQL commands via unsanitized date parameters in POST requests. This af...

CVE-2021-43851

HIGH CVSS 8.1 Dec 22, 2021

CVE-2021-43851 is an SQL injection vulnerability in Anuko Time Tracker that allows attackers to execute arbitrary SQL commands via the 'group' and 'status' parameters in POST requests. This affects al...