PT-2025-54470 · Titra · Titra

CVE-2025-69288

·

Publicado

2025-12-31

·

Atualizado

2026-01-02

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Titra versions prior to 0.99.49
Description Titra is open source project time tracking software. Prior to version 0.99.49, authenticated Admin users can modify the timeEntryRule value in the database. This value is then passed to a NodeVM value to execute as code without sanitization, leading to Remote Code Execution. The timeEntryRule is a vulnerable parameter.
Recommendations Update to version 0.99.49 to address this issue.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69288
GHSA-PQGX-6WG3-GMVR

Produtos afetados

Titra