Anuko Time Tracker versions prior to 1.20.0.5642 are vulnerable to UNION SQL injection and time-based blind SQL injection in the Puncher plugin. The vulnerability arises from the reuse of code that fails to sanitize a date parameter in POST requests, allowing attackers to inject arbitrary SQL into database queries.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit (anuko_exploit.py) and a README.md for CVE-2022-24707, a time-based SQL injection vulnerability in Anuko Time Tracker version 1.20.0 and below. The exploit automates the process of authenticating to the target web application, enabling and using the Puncher plugin, and extracting all user credentials from the tt_users database table by exploiting the SQL injection vulnerability in the Puncher feature. The script requires valid credentials and a properly configured target. It interacts with several endpoints (login.php, puncher.php, time_edit.php) to perform authentication, session management, and the actual SQL injection. The README provides detailed usage instructions, prerequisites, and an example command. The exploit is operational, providing a working attack that can extract sensitive data if the target is vulnerable and properly configured.
This repository contains a proof-of-concept exploit (exploit.py) for CVE-2022-24707, a SQL injection vulnerability in the Puncher plugin of Anuko Time Tracker version 1.20.0.5640. The exploit is implemented in Python and requires valid user credentials to authenticate to the target application. It automates the process of logging in, selecting a project, starting a puncher entry, and then exploiting the SQL injection vulnerability by injecting a crafted SQL query into the 'date' parameter of a POST request to /puncher.php. The result of the SQL query is retrieved from the application's web interface, and the created puncher entry is deleted to clean up traces. The repository consists of two files: a README.md with usage instructions and exploit details, and exploit.py, which contains the full exploit logic. The exploit demonstrates the ability to enumerate database tables or run arbitrary SQL queries, confirming the vulnerability's impact.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.