cbcvebase.
CVE-2020-15255
published 2020-10-16

CVE-2020-15255: In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as…

PriorityP342high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EXPLOIT
EPSS
3.46%
87.6th percentile
In Anuko Time Tracker before verion 1.19.23.5325, due to not properly filtered user input a CSV export of a report could contain cells that are treated as formulas by spreadsheet software (for example, when a cell value starts with an equal sign). This is fixed in version 1.19.23.5325.

Affected

2 ranges
VendorProductVersion rangeFixed in
anukotime_tracker< 1.19.23.53251.19.23.5325
anukotimetracker< 1.19.23.53251.19.23.5325

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.