edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Time_tracking_software | Scheduling_management.com | 3.0 (including) | 3.0 (including) |