Executive brief
Trexom TrxTimeATTENDANCE is an attendance and time-tracking system used by organizations to monitor employee presence. An unauthenticated remote attacker can exploit a command injection flaw in the ping.php endpoint to execute arbitrary code on affected systems, potentially leading to complete system compromise and unauthorized access to sensitive HR and operational data.
Technical details
The vulnerability is an OS command injection (CWE-78) in the ping.php endpoint caused by insufficient input validation and sanitization. An unauthenticated remote attacker can send a specially crafted request to the vulnerable endpoint with malicious parameters that are passed unsanitized to system command execution functions, allowing arbitrary OS command execution. This results in remote code execution with the privileges of the web server process. The vulnerability affects TrxTimeATTENDANCE versions 1.0.5 through 1.9.5 inclusive. Patches are available and users are advised to update to the latest version and restrict network exposure of the ping.php endpoint via firewall rules.
Affected products
- Trexom TrxTimeATTENDANCE 1.0.5 through 1.9.5 inclusive
Timeline
- 2026-09-15: disclosed: Vulnerability disclosed by CSIRT Italia and Trexom