A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. The impacted element is an unknown function of the component Edit Ticket Page. Performing manipulation of the argument Title results in csv injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Configurations
No configuration.
History
27 Oct 2025, 08:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-27 08:15
Updated : 2025-10-27 13:19
NVD link : CVE-2025-12249
Mitre link : CVE-2025-12249
CVE.ORG link : CVE-2025-12249
JSON object : View
Products Affected
No product.
