CRITICAL🇵🇱 Wersja polska

CVE-2025-69288

CVSS 9.1v3.1pub. 2025-12-31upd. 2026-01-13

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.

🤖 AI Analysis
How it works

An authenticated user with administrator privileges can modify the value of the timeEntryRule field in the database. The modified value is then passed without any sanitization to the NodeVM environment, where it is executed as code. This allows injection and execution of arbitrary JavaScript code on the server side.

Impact

An attacker with administrator privileges can gain full control of the server, access sensitive data, modify or destroy system resources, and use the compromised server as a launching point for further attacks.

Mitigation & patch

Titra should be updated to version 0.99.49 or later, which eliminates the described vulnerability. Patch available in the manufacturer's references on GitHub.

Who is affected

Titra in versions earlier than 0.99.49.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Kromit Titra

    APP
    Kromit
    < 0.99.49
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2022-2595CRITICAL10.0PL ✓same product

Nieprawidłowa autoryzacja w Kromit Titra — pełny dostęp zdalny

CVE-2022-2098CRITICAL9.8PL ✓same product

Zbyt słabe wymagania dotyczące haseł w Kromit Titra (CWE-521)

CVE-2022-2027HIGH8.0same product

Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77....

CVE-2026-21695MEDIUM4.3same product

Titra to otwarte oprogramowanie do śledzenia czasu pracy. W wersjach 0.99.49 i wcześniejszych API ma podatność...

CVE-2026-21694MEDIUM6.8same product

Titra to oprogramowanie do śledzenia czasu pracy o otwartym kodzie źródłowym. W wersjach 0.99.49 i starszych w...