CVE-2020-27422
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/11/2020
Last modified:
30/11/2020
Description
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:anuko:time_tracker:*:*:*:*:*:*:*:* | 1.19.23.5311 (including) |
To consult the complete list of CPE names with products and versions, see this page



