Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.
An authenticated user with administrator privileges can modify the value of the timeEntryRule field in the database. The modified value is then passed without any sanitization to the NodeVM environment, where it is executed as code. This allows injection and execution of arbitrary JavaScript code on the server side.
An attacker with administrator privileges can gain full control of the server, access sensitive data, modify or destroy system resources, and use the compromised server as a launching point for further attacks.
Titra should be updated to version 0.99.49 or later, which eliminates the described vulnerability. Patch available in the manufacturer's references on GitHub.
Titra in versions earlier than 0.99.49.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HKromit Titra
APPKromit< 0.99.49
Related vulnerabilities
Nieprawidłowa autoryzacja w Kromit Titra — pełny dostęp zdalny
Zbyt słabe wymagania dotyczące haseł w Kromit Titra (CWE-521)
Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77....
Titra to otwarte oprogramowanie do śledzenia czasu pracy. W wersjach 0.99.49 i wcześniejszych API ma podatność...
Titra to oprogramowanie do śledzenia czasu pracy o otwartym kodzie źródłowym. W wersjach 0.99.49 i starszych w...