CSV Injection Vulnerability in Axosoft Scrum and Bug Tracking
CVE-2025-11279
Key Information:
- Vendor
Axosoft
- Status
- Vendor
- CVE Published:
- 5 October 2025
Badges
What is CVE-2025-11279?
A recent vulnerability has been identified in Axosoft Scrum and Bug Tracking version 22.1.1.11545, specifically within the Add Work Item Page component. This issue allows remote attackers to manipulate the Title argument, leading to potential CSV injection. Such an exploit could enable attackers to execute malicious scripts through improperly handled CSV files. Despite earlier notifications of this vulnerability, the vendor has not yet provided a response.
Affected Version(s)
Scrum and Bug Tracking 22.1.1.11545
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved