Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add action with a modified GroupID in a direct request to Customize.asp.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Tasktracker | Geckovich | 1.4 (including) | 1.4 (including) |
| Tasktracker_pro | Geckovich | * | 1.5 (including) |