CVE-2025-69288
PUBLISHED 12/31/2025 a0819718-46f1-4df5-94e2-005712e83aaa
Technical Description
Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.
Affected Products
kromitgmbh
titra
< 0.99.49
References
https://github.com/kromitgmbh/titra/security/advisories/GHSA-pqgx-6wg3-gmvr
https://github.com/kromitgmbh/titra/security/advisories/GHSA-pqgx-6wg3-gmvr
https://github.com/kromitgmbh/titra/commit/2e2ac5cbeed47a76720b21c7fde0214a242e065e
https://github.com/kromitgmbh/titra/commit/2e2ac5cbeed47a76720b21c7fde0214a242e065e
https://github.com/kromitgmbh/titra/releases/tag/0.99.49
https://github.com/kromitgmbh/titra/releases/tag/0.99.49
9.1 CVSS v3.1
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Impact Analysis
Attack Vector Network
Attack Complexity Low
Privileges Required None