In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an malicious user to use the same link to takeover the account.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
anuko time tracker |