Vulnerabilities (CVE)

Filtered by vendor Efrotech Subscribe
Filtered by product Timetrax
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-39250 1 Efrotech 1 Timetrax 2025-07-08 N/A 9.8 CRITICAL
EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface.
CVE-2025-46157 1 Efrotech 1 Timetrax 2025-06-26 N/A 9.9 CRITICAL
An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave request form