CVE-2024-41805: Tracksapp Tracks
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Tracks, a Getting Things Done (GTD) web application, is vulnerable to reflected cross-site scripting in versions prior to 2.7.1. Reflected cross-site scripting enables execution of malicious JavaScript in the context of a user’s browser if that user clicks on a malicious link, allowing phishing attacks that could lead to credential theft. Tracks version 2.7.1 is patched. No known complete workarounds are available.
Affected products
- Tracksapp Tracks: before 2.7.1 (fixed in 2.7.1); version 2.7.1 only
Published 2024-07-26. Last modified 2026-06-17.