Vulnerability Description
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Anuko | Time Tracker | <= 1.19.23.5311 |
Related Weaknesses (CWE)
References
- https://packetstormsecurity.com/files/160052/Anuko-Time-Tracker-1.19.23.5311-MisThird Party AdvisoryVDB Entry
- https://packetstormsecurity.com/files/160052/Anuko-Time-Tracker-1.19.23.5311-MisThird Party AdvisoryVDB Entry
FAQ
What is CVE-2020-27423?
CVE-2020-27423 is a vulnerability with a CVSS score of 7.5 (HIGH). Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox
How severe is CVE-2020-27423?
CVE-2020-27423 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27423?
Check the references section above for vendor advisories and patch information. Affected products include: Anuko Time Tracker.