Description
Anuko Time Tracker is an open source, web-based time tracking application written in PHP. In Time Tracker before version 1.19.27.5431 a Cross site request forgery (CSRF) vulnerability existed. The nature of CSRF is that a logged on user may be tricked by social engineering to click on an attacker-provided form that executes an unintended action such as changing user password. The vulnerability is fixed in Time Tracker version 1.19.27.5431. Upgrade is recommended. If upgrade is not practical, introduce ttMitigateCSRF() function in /WEB-INF/lib/common.php.lib using the latest available code and call it from ttAccessAllowed().
References (3)
Core 3
Core References
Third Party Advisory x_refsource_confirm
https://github.com/anuko/timetracker/security/advisories/GHSA-pgpx-rfvj-9g4f
Patch, Third Party Advisory x_refsource_misc
https://github.com/anuko/timetracker/commit/e3f8222ee308322942bcebcd86b78ecf19382563
Patch, Third Party Advisory x_refsource_misc
https://github.com/anuko/timetracker/commit/e77be7eea69df5d52e19f9f25b5b89a0e66a5b8e
Scores
CVSS v3
5.4
EPSS
0.0022
EPSS Percentile
44.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Details
CWE
CWE-352
Status
published
Products (1)
anuko/time_tracker
< 1.19.27.5431
Published
Apr 13, 2021
Tracked Since
Feb 18, 2026