VYPR

Time Tracker

by Time Tracker Project

CVEs (3)

  • CVE-2023-32306HigMay 12, 2023
    risk 0.57cvss 8.8epss 0.01

    Time Tracker is an open source time tracking system. A time-based blind injection vulnerability existed in Time Tracker reports in versions prior to 1.22.13.5792. This was happening because the `reports.php` page was not validating all parameters in POST requests. Because some…

  • CVE-2023-32066MedMay 9, 2023
    risk 0.00cvss 5.4epss 0.00

    Time Tracker is an open source time tracking system. The week view plugin in Time Tracker versions 1.22.11.5782 and prior was not escaping titles for notes in week view table. Because of that, it was possible for a logged in user to enter notes with elements of JavaScript. Such…

  • CVE-2015-6751Aug 31, 2015
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the Time Tracker module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via a (1) note added to a time entry or an (2) activity used to…