CVE-2020-27423

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/11/2020
Last modified:
01/12/2020

Description

Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:anuko:time_tracker:*:*:*:*:*:*:*:* 1.19.23.5311 (including)