CVE-2025-46157

An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave request form
References
Link Resource
http://efrotech.com Product
http://timetrax.com Broken Link
https://github.com/morphine009/CVE-2025-46157 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:efrotech:timetrax:1.0:*:*:*:*:*:*:*

History

26 Jun 2025, 15:53

Type Values Removed Values Added
References () http://efrotech.com - () http://efrotech.com - Product
References () http://timetrax.com - () http://timetrax.com - Broken Link
References () https://github.com/morphine009/CVE-2025-46157 - () https://github.com/morphine009/CVE-2025-46157 - Exploit, Third Party Advisory
CPE cpe:2.3:a:efrotech:timetrax:1.0:*:*:*:*:*:*:*
First Time Efrotech timetrax
Efrotech

23 Jun 2025, 20:16

Type Values Removed Values Added
Summary
  • (es) Un problema en EfroTech Time Trax v.1.0 permite que un atacante remoto ejecute código arbitrario a través de la función de adjuntar archivos en el formulario de solicitud de licencia.

18 Jun 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-18 14:15

Updated : 2025-06-26 15:53


NVD link : CVE-2025-46157

Mitre link : CVE-2025-46157

CVE.ORG link : CVE-2025-46157


JSON object : View

Products Affected

efrotech

  • timetrax
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type