CVE-2025-11279 Details
Description
A vulnerability was detected in Axosoft Scrum and Bug Tracking 22.1.1.11545. This issue affects some unknown processing of the component Add Work Item Page. The manipulation of the argument Title results in csv injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A CSV injection vulnerability has been identified in Axosoft Scrum and Bug Tracking version 22.1.1.11545. This vulnerability resides in the Add Work Item Page component, where the Title argument can be manipulated to inject malicious payloads. A low-privileged attacker can exploit this by creating a new work item and injecting a payload into the title. When an administrator exports the work items list to CSV and opens the file, the injected payload is executed, potentially leading to a reverse shell on the admin's machine.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 5, 2025CISA-ADP
Assessed Oct 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://drive.google.com/file/d/1Lw9_KYblnhg7FQU70G0SgH_VyYRUD-rX/view?usp=sharing | [email protected] | ExploitPartial Content |
| https://vuldb.com/?ctiid.327013 | [email protected] | AdvisoryExploitPermission Required |
| https://vuldb.com/?id.327013 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.659422 | [email protected] | AdvisoryExploitPartial Content |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1236 | Improper Neutralization of Formula Elements in a CSV File | [email protected] |
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Axosoft Scrum and Bug Tracking | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Oct 5, 2025 | New CVE Received | [email protected] |
Volerion