CVE-2020-27422 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 7.9% (pctl 94)
Patch early
A public exploit exists.
Description
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 7.86% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-613 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-11-16 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| anuko | time tracker |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Anuko Time Tracker 1.19.23.5311 - Password Reset leading to Account Takeover | 2020-12-02 |
References
→ the Explorer · watch your stack · NVD