Missing Authorization in titra - #VU151679

 

Missing Authorization in titra - #VU151679

Published: September 22, 2026


Vulnerability identifier: #VU151679
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete other users' project time entries.

The vulnerability exists due to missing authorization in the deleteTimeCardsForWeek DDP method when processing timecard deletion requests. A remote user can invoke the method with a matching project, task, and date range to delete other users' time entries.

Exploitation requires another user's entries to match the specified project, task, and date range.


Affected software

titra

Remediation

Install security update from vendor's website.

titra - update to 1.1.0

External References

Related Security Bulletins