7.5
CVSSv3

CVE-2020-27423

Published: 16/11/2020 Updated: 01/12/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows malicious user to perform Denial of Service attack on any legitimate user's mailbox

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

anuko time tracker

Exploits

Anuko Time Tracker version 119235311 suffers from an implementation flaw where password reset emails can be continuously triggered against unsuspecting users ...