CVE-2022-24707 describes a UNION SQL injection and time-based blind injection vulnerability in the Puncher plugin of Anuko Time Tracker versions prior to 1.20.0.5642. This flaw, stemming from unsanitized date parameters in POST requests, allows authenticated attackers to craft malicious SQL queries against the Time Tracker database. With a CVSS score of 8.8 (High), successful exploitation could lead to high impact on confidentiality, integrity, and availability. While not actively exploited in the wild and lacking Metasploit/Nuclei modules, an authenticated SQLi exploit (EDB-50915) is publicly available, though community discussion and media coverage remain low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.20.0.5642CPE matchmatch criteria | cpe:2.3:a:anuko:time_tracker:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.