
Nuclei template for unauthenticated SQL injection in Efrotech TimeTrax (CVE-2024-39250), enabling automated vulnerability scanning and exploitation of HR attendance tracking systems.
Efrotech's (http://www.efrotech.com/) TimeTrax (https://etimetrax.com/) is a Human Resources attendance tracking program, and I found an unauthenticated SQL Injection vulnerability. It is easy to execute the attack vector, so I created a nuclei template.