CVE-2023-32066
Last modified
CVE-2023-32066 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Time Tracker is an open source time tracking system. The week view plugin in Time Tracker versions 1.22.11.5782 and prior was not escaping titles for notes in week view table. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Time Tracker is an open source time tracking system. The week view plugin in Time Tracker versions 1.22.11.5782 and prior was not escaping titles for notes in week view table. Because of that, it was possible for a logged in user to enter notes with elements of JavaScript. Such script could then be executed in user browser on subsequent requests to week view. This issue is fixed in version 1.22.12.5783. As a workaround, use `htmlspecialchars` when calling `$field->setTitle` on line #245 in the `week.php` file, as happens in version 1.22.12.5783.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Anuko | Time Tracker | < 1.22.12.5783 |
References
- https://github.com/anuko/timetracker/security/advisories/GHSA-jw2g-8wvp-9frwThird Party Advisory
- https://github.com/anuko/timetracker/security/advisories/GHSA-jw2g-8wvp-9frwThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-32066?
How severe is CVE-2023-32066?
How do I fix CVE-2023-32066?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-32060DHIS2 Core contains the service layer and Web API for DHIS2,…6.5
- CVE-2023-32061Discourse is an open source discussion platform. Prior to ve…5.3
- CVE-2023-32062OroPlatform is a package that assists system and user calend…4.3
- CVE-2023-32063OroCalendarBundle enables a Calendar feature and related fun…5
- CVE-2023-32064OroCommerce package with customer portal and non authenticat…4.3
- CVE-2023-32065OroCommerce is an open-source Business to Business Commerce …5.8
- CVE-2023-32067c-ares is an asynchronous resolver library. c-ares is vulner…7.5
- CVE-2023-32068XWiki Platform is a generic wiki platform offering runtime s…6.1
- CVE-2023-32069XWiki Platform is a generic wiki platform. Starting in versi…8.8
- CVE-2023-3207Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2023-32070XWiki Platform is a generic wiki platform. Prior to version …6.1
- CVE-2023-32071XWiki Platform is a generic wiki platform. Starting in versi…9
Are you affected by CVE-2023-32066?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
