Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add action with a modified GroupID in a direct request to Customize.asp.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tasktracker | Geckovich | 1.4 (including) | 1.4 (including) |
Tasktracker_pro | Geckovich | * | 1.5 (including) |