216.73.216.6

CVE-2025-69288

· Published 31/12/2025 22:15 · Modified 31/12/2025 22:15

Labels: CVE-2025-69288 2025-12-31CVE-2025-69288CWE-20[email protected]

Essential information

Published
31/12/2025 22:15
Modified
31/12/2025 22:15
Author
Creator
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
titra / titra cpe:2.3:a:titra:titra:<0.99.49:*:*:*:*:*:*:*

References