CVE-2025-60291

An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unauthorized attackers to access specific routes and modify database connection configurations.
Configurations

No configuration.

History

27 Oct 2025, 16:15

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
References () https://github.com/M00nBack/CVE_Request/blob/main/eSSL%20Security/eTimeTrackLite.md - () https://github.com/M00nBack/CVE_Request/blob/main/eSSL%20Security/eTimeTrackLite.md -

27 Oct 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-27 14:15

Updated : 2025-10-30 15:05


NVD link : CVE-2025-60291

Mitre link : CVE-2025-60291

CVE.ORG link : CVE-2025-60291


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control