Vulnerability Description
An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unauthorized attackers to access specific routes and modify database connection configurations.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/M00nBack/CVE_Request/blob/main/eSSL%20Security/eTimeTrackLite
- https://www.esslsecurity.com/
- https://github.com/M00nBack/CVE_Request/blob/main/eSSL%20Security/eTimeTrackLite
FAQ
What is CVE-2025-60291?
CVE-2025-60291 is a vulnerability with a CVSS score of 9.1 (CRITICAL). An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unauthorized attackers to access specific routes and modify database connection confi...
How severe is CVE-2025-60291?
CVE-2025-60291 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-60291?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.