Missing Authorization in titra - #VU151679
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to delete other users' project time entries.
The vulnerability exists due to missing authorization in the deleteTimeCardsForWeek DDP method when processing timecard deletion requests. A remote user can invoke the method with a matching project, task, and date range to delete other users' time entries.
Exploitation requires another user's entries to match the specified project, task, and date range.